Executive brief
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browse to a malicious URL via a crafted HTML page. This issue stems from insufficient validation of untrusted input in Intents on Android versions of the browser.
Affected products
- Google Chrome prior to 95.0.4638.69
- Microsoft Edge
- Opera Software Opera
Timeline
- 2021-10-28: patched: Stable channel update for desktop 95.0.4638.69
- 2021-11-03: disclosed: Published in NVD and added to CISA KEV
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog