CVE-2021-37980Google Chrome vulnerability

6 documents6 sources
Severity
7.4HIGHNVD
EPSS
0.3%
top 45.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 24

Description

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 2.8 | Impact: 4.0

Affected Packages6 packages

CVEListV5google/chromeunspecified94.0.4606.81
NVDgoogle/chrome< 94.0.4606.81
debiandebian/chromium< chromium 97.0.4692.71-0.1 (bookworm)
Debianchromium/chromium< 97.0.4692.71-0.1~deb11u1+3

Also affects: Debian Linux 10.0, 11.0, Fedora 33

🔴Vulnerability Details

2
GHSA
GHSA-83r7-7p8q-v697: Inappropriate implementation in Sandbox in Google Chrome prior to 942022-05-24
OSV
CVE-2021-37980: Inappropriate implementation in Sandbox in Google Chrome prior to 942021-11-02

📋Vendor Advisories

3
Microsoft
Chromium: CVE-2021-37980 Inappropriate implementation in Sandbox2021-10-12
Chrome
Stable Channel Update for Desktop: CVE-2021-379802021-10-07
Debian
CVE-2021-37980: chromium - Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 a...2021