CVE-2021-38000: Google Chromium Intents Improper Input Validation Vulnerability
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1Fixed in 118.0.5993.70-1~deb11u1Fixed in 116.0.5845.180-1~deb12u1Fixed in 118.0.5993.70-1~deb12u1Fixed in 118.0.5993.70-1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 95.0.4638.69
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-38000?
CVE-2021-38000 is a vulnerability in Google Chromium that allows a remote attacker to browse to a malicious URL via a crafted HTML page.
Which software is affected by CVE-2021-38000?
CVE-2021-38000 affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge.
How severe is CVE-2021-38000?
CVE-2021-38000 has a severity rating of 6.1, which is considered medium.
How can I fix CVE-2021-38000?
To fix CVE-2021-38000, ensure that your web browser, such as Google Chrome or Microsoft Edge, is updated to the latest version provided by the vendor.
Where can I find more information about CVE-2021-38000?
You can find more information about CVE-2021-38000 in the references provided: [link1](https://security-tracker.debian.org/tracker/CVE-2021-38000), [link2](https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html), [link3](https://crbug.com/1249962).