CVE-2021-37980

high
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
8.0

Description

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-37980

OS impact

OSVersionStatusFixed in
arch archfixed4.3.2439.44-1
debian debianbookwormfixed97.0.4692.71-0.1
debian debianbullseyefixed97.0.4692.71-0.1~deb11u1
debian debianforkyfixed97.0.4692.71-0.1
debian debiansidfixed97.0.4692.71-0.1
debian debiantrixiefixed97.0.4692.71-0.1

References

Verify integrity in audit chain (admin only). AS-IS.