First published: Fri Apr 16 2021(Updated: )
Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.
Credit: chrome-cve-admin@google.com Daniel Genkin MichiganAyush Agarwal MichiganUniversity MichiganEyal Ronen AdelaideShaked Yehezkel AdelaideTel Aviv University AdelaideSioli O’Connell AdelaideUniversity Adelaide TechnologyJason Kim TechnologyGeorgia Institute Technology
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | <=90.0.4430.212-1~deb10u1 | 116.0.5845.180-1~deb11u1 118.0.5993.70-1~deb11u1 116.0.5845.180-1~deb12u1 118.0.5993.70-1~deb12u1 118.0.5993.70-1 |
Google Chrome | <94.0.4606.54 | 94.0.4606.54 |
Google Chrome | <94.0.4606.54 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =35 | |
Debian | =10.0 | |
Debian | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-37963 is classified as a medium severity vulnerability allowing side-channel information leakage.
To remediate CVE-2021-37963, upgrade Google Chrome to version 94.0.4606.54 or later.
CVE-2021-37963 affects all Google Chrome versions prior to 94.0.4606.54.
CVE-2021-37963 can be exploited through a crafted HTML page to circumvent site isolation.
Yes, Debian versions using Chromium versions up to 90.0.4430.212-1~deb10u1 are vulnerable to CVE-2021-37963.