Chrome 94 Update Patches Actively Exploited Zero-Day Vulnerability

Google has shipped an urgent Chrome update to address yet another zero-day vulnerability that has been actively exploited in attacks.

Tracked as CVE-2021-37973, the security bug is described as a use-after-free issue in the Portals API, a web page navigation technology that pre-renders content when transitioning to a new page, for a seamless experience.

Google did not provide technical details on CVE-2021-37973, but warned that an exploit for it exists in the wild. The search giant credited Clément Lecigne from Google TAG and Sergei Glazunov and Mark Brand from Google Project Zero for reporting the vulnerability.