CVE-2021-37988: Use after free in Profiles
Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-37988?
CVE-2021-37988 has a medium severity rating due to potential heap corruption allowing remote exploitation.
How do I fix CVE-2021-37988?
To fix CVE-2021-37988, update Google Chrome to version 95.0.4638.54 or later or update the Chromium package on Debian to the specified remedied versions.
What versions of Google Chrome are affected by CVE-2021-37988?
Google Chrome versions prior to 95.0.4638.54 are affected by CVE-2021-37988.
What is the potential impact of CVE-2021-37988?
The potential impact of CVE-2021-37988 includes the possibility of remote attackers exploiting heap corruption through malicious HTML pages.
Can CVE-2021-37988 be exploited without user interaction?
CVE-2021-37988 requires user interaction in the form of specific gestures to exploit the vulnerability.