CVE-2021-37973: Google Chromium Portals Use-After-Free Vulnerability
Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
Other sources
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 118.0.5993.70-1~deb11u1Fixed in 116.0.5845.180-1~deb12u1Fixed in 118.0.5993.70-1~deb12u1Fixed in 118.0.5993.70-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 94.0.4606.61
Event History
Frequently Asked Questions
What is CVE-2021-37973?
CVE-2021-37973 is a use-after-free vulnerability in Google Chromium Portals.
How does CVE-2021-37973 impact web browsers?
CVE-2021-37973 can potentially allow a remote attacker to perform a sandbox escape via a crafted HTML page on web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
Which software versions are affected by CVE-2021-37973?
CVE-2021-37973 affects Google Chromium versions up to and including 94.0.4606.61, Google Chrome versions up to and including 94.0.4606.61, and Debian Chromium versions up to and including 90.0.4430.212-1~deb10u1.
What is the severity of CVE-2021-37973?
CVE-2021-37973 has a severity rating of 9.6 (Critical).
How can I mitigate CVE-2021-37973?
To mitigate CVE-2021-37973, users should update their Chromium-based web browsers to the latest available versions provided by the respective vendors.