CVE-2021-37996: Insufficient validation of untrusted input in Downloads
Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a malicious file.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-37996?
CVE-2021-37996 is rated as a high severity vulnerability due to its potential to allow remote attackers to bypass navigation restrictions.
How do I fix CVE-2021-37996?
To fix CVE-2021-37996, users should update Google Chrome to version 95.0.4638.54 or later, or upgrade their Debian system to a patched version of Chromium.
Which versions of Google Chrome are affected by CVE-2021-37996?
CVE-2021-37996 affects all Google Chrome versions prior to 95.0.4638.54.
Can CVE-2021-37996 affect Debian systems as well?
Yes, CVE-2021-37996 also affects Debian-based systems using vulnerable versions of Chromium before the fix was released.
What type of attack does CVE-2021-37996 enable?
CVE-2021-37996 enables attackers to bypass navigation restrictions through malicious file downloads.