CVE-2021-37976: Information leak in core
Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 118.0.5993.70-1~deb11u1Fixed in 116.0.5845.180-1~deb12u1Fixed in 118.0.5993.70-1~deb12u1Fixed in 118.0.5993.70-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 94.0.4606.71
Event History
Frequently Asked Questions
What is CVE-2021-37976?
CVE-2021-37976 refers to an information disclosure vulnerability in Google Chromium.
What is the severity of CVE-2021-37976?
CVE-2021-37976 has a severity rating of 6.5 (Medium).
How does CVE-2021-37976 allow an attacker to obtain sensitive information?
CVE-2021-37976 allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Which software is affected by CVE-2021-37976?
CVE-2021-37976 affects Google Chromium, Google Chrome, Fedora, and Debian Linux.
How can I fix CVE-2021-37976?
To fix CVE-2021-37976, update to the patched versions provided by the respective vendors.