LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-37973: Google Chromium Portals Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-37973 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML…

CVE-2021-37973 is a use-after-free vulnerability in Google Chromium Portals. It can allow a remote attacker who has already compromised the renderer process to potentially escape the sandbox by means of a crafted HTML page. Because many browsers are built on Chromium, the issue can affect products such as Google Chrome and Microsoft Edge. For defenders this matters because a sandbox escape expands what an attacker can do after initial code execution in the browser, increasing the chance of further compromise on the endpoint.

Public detail is limited to the description above; exact affected builds, scoring, and full technical mechanics must be confirmed against the vendor advisory. CISA notes that the required action is to apply updates per vendor instructions. Ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-416 (use-after-free). In this class of flaw, memory that has already been freed is later accessed again. When that happens inside a browser component, an attacker who can influence allocation and freeing patterns may be able to corrupt memory or redirect control flow.

According to the CISA summary, the vulnerability resides in Chromium Portals. An attacker who has already compromised the renderer process can supply a crafted HTML page that triggers the use-after-free, with the potential result of a sandbox escape. The summary does not provide exploit primitives, heap-spray details, or step-by-step trigger sequences; defenders should treat those as unknown and rely on the vendor advisory for any deeper technical analysis. The practical implication is that successful abuse moves the attacker from a restricted renderer context toward greater privileges on the host, which is why timely patching of Chromium-based browsers is important.

Am I affected? How to find it in your systems

Chromium Portals code ships inside Chromium-based web browsers. Typical locations include end-user workstations, VDI images, kiosks, and any managed browser deployments of Google Chrome, Microsoft Edge, or other Chromium derivatives.

How to remediate

Patching is the primary remediation. Apply the vendor updates that address CVE-2021-37973 as instructed in the official Chromium, Chrome, or Edge security bulletins. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

When immediate patching is not possible, reduce risk with compensating controls while you schedule the update.

These measures do not eliminate the vulnerability; they only buy time until the vendor update can be applied.

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to endpoint compromise and subsequent data exposure. If you have reason to believe systems were targeted before patching, follow your incident-response process: isolate affected hosts, preserve volatile evidence, and hunt for post-exploitation activity. Ransomware use is not documented for this CVE, but any sandbox escape still warrants thorough review. As a simple additional check, users can run a free exposure scan of their email addresses against known breach data sets to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium Portals
WeaknessCWE-416
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities