CVE-2021-37964: Inappropriate implementation in ChromeOS Networking
Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 118.0.5993.70-1~deb11u1Fixed in 116.0.5845.180-1~deb12u1Fixed in 118.0.5993.70-1~deb12u1Fixed in 118.0.5993.70-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 94.0.4606.54
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-37964.
What is the severity of CVE-2021-37964?
The severity of CVE-2021-37964 is medium with a CVSS score of 3.3.
What is the affected software for CVE-2021-37964?
The affected software for CVE-2021-37964 includes Google Chrome on ChromeOS prior to version 94.0.4606.54 and Chromium on Debian Linux versions 10.0 and 11.0.
How can an attacker exploit CVE-2021-37964?
An attacker with a rogue wireless access point can potentially carry out a wifi impersonation attack by using a crafted ONC file.
How do I fix CVE-2021-37964?
To fix CVE-2021-37964, update Google Chrome on ChromeOS to version 94.0.4606.54 or later.