CVE-2021-37994: Inappropriate implementation in iFrame Sandbox
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-37994?
CVE-2021-37994 has been classified as a high-severity vulnerability affecting Google Chrome and Chromium-based browsers.
How do I fix CVE-2021-37994?
To fix CVE-2021-37994, update Google Chrome to version 95.0.4638.54 or later, or update your Chromium package to the recommended versions listed by Debian.
What kind of attack can exploit CVE-2021-37994?
CVE-2021-37994 can be exploited by a remote attacker to bypass navigation restrictions through a specially crafted HTML page.
Which versions of Chrome are affected by CVE-2021-37994?
CVE-2021-37994 affects Google Chrome versions prior to 95.0.4638.54.
Is Debian affected by CVE-2021-37994?
Yes, Debian users are affected if they are using vulnerable versions of the Chromium browser prior to the recommended updates.