CERT-In Advisory
CIAD-2021-0037
Remote Code Execution Vulnerability in Google Chrome
Original Issue Date: September 25, 2021
Severity Rating: High
Software Affected
- Google Chrome version prior to 94.0.4606.61 for Windows, Mac, and Linux
Overview
A vulnerability has been reported in Google Chrome which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
Description
This vulnerability exists in Google Chrome due to a use-after-free error when processing HTML content within the Portals component in Google Chrome. A remote attacker could exploit this vulnerability by creating a specially crafted web page and triggering a use-after-free error and execute arbitrary code on the system.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code and take control of a targeted system.
Note: This vulnerability is currently being exploited in the wild, users are advised to apply patches urgently.
Solution
Upgrade to Google chrome version 94.0.4606.61 for Windows, Mac, and Linux
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_24.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_24.html
References
Google Chrome
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_24.html
CVE Name
CVE-2021-37973
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|