NVD disclosure day

Published threat advisories for October 8, 2021

CVE advisoryKnown Exploit

CVE-2021-37976

Google Chrome Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Google Chrome's memory handling could allow attackers to access sensitive information from process memory via a crafted webpage. This impacts organizations using affected Chrome versions and exposes them to potential data breaches. Prompt application of vendor updates is recommended.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-37975

Google Chrome Use-After-Free Vulnerability Allows Remote Exploitation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's V8 engine could allow remote attackers to corrupt memory via a crafted HTML page. This may lead to system compromise and data loss. Organizations using affected versions should update their software promptly.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-37973

Google Chrome Sandbox Escape Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory management flaw in Google Chrome's Portals feature could allow a remote attacker to escape the browser's sandbox. This may result in unauthorized system access or data compromise. Affected organizations face business risk if employees interact with malicious web pages.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2021-30633

Google Chrome Sandbox Escape Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Google Chrome's Indexed DB API could allow an attacker with renderer process control to escape the browser sandbox via a crafted HTML page. This impacts organizations using affected Chrome versions by posing a risk of unauthorized system access and data compromise. Organizations should update Chrome

• CISA KEV