MEDIUM

CVE-2021-38000

Google Chrome 2021-11-23 CVSS v3.1
CVSS
6.1
KEV

Description

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

Summary dbcve.org

Insufficient validation of untrusted input in Android Intents in Google Chrome on Android prior to version 95.0.4638.69 allows a remote attacker to arbitrarily navigate the browser to a malicious URL by tricking users into visiting a crafted HTML page.

Mitigation

Update Google Chrome for Android to version 95.0.4638.69 or later to patch the Intent validation vulnerability.

Proof of Concept

Weakness (CWE)

CWE-601 Open Redirect
CWE-20 Improper Input Validation

EPSS Score

4.95%
Probability of exploitation in next 30 days
91.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE