Junglewise Threat Intelligence

CVE-2021-38000: Google Chromium Intents Improper Input Validation Vulnerability

CVE-2021-38000 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2021-11-03

Technologies: Google Chrome, Microsoft Edge, Opera Software Opera. Vendors: Google, Microsoft, Opera Software.

Executive brief

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browse to a malicious URL via a crafted HTML page. This issue stems from insufficient validation of untrusted input in Intents on Android versions of the browser.

Affected products

  • Google Chrome prior to 95.0.4638.69
  • Microsoft Edge
  • Opera Software Opera

Timeline

  • 2021-10-28: patched: Stable channel update for desktop 95.0.4638.69
  • 2021-11-03: disclosed: Published in NVD and added to CISA KEV
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats