CVE-2021-37990: Inappropriate implementation in WebView
Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-37990?
CVE-2021-37990 is classified as a high-severity vulnerability due to its potential to leak cross-origin data.
What versions are affected by CVE-2021-37990?
CVE-2021-37990 affects Google Chrome versions prior to 95.0.4638.54 and certain versions of the Chromium package on Debian.
How do I fix CVE-2021-37990?
To fix CVE-2021-37990, update Google Chrome to version 95.0.4638.54 or later and ensure you have the latest Chromium package installed.
Who is impacted by CVE-2021-37990?
Users of Google Chrome on Android prior to version 95.0.4638.54 and certain Debian users are impacted by CVE-2021-37990.
Can CVE-2021-37990 be exploited remotely?
Yes, CVE-2021-37990 allows remote attackers to potentially exploit the vulnerability to leak sensitive cross-origin data.