CVE-2021-38010: Inappropriate implementation in service workers
Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-38010?
CVE-2021-38010 is classified as a high-severity vulnerability due to the potential for a remote attacker to bypass site isolation.
How do I fix CVE-2021-38010?
You can fix CVE-2021-38010 by updating Google Chrome or Chromium to version 96.0.4664.45 or later.
Which versions are affected by CVE-2021-38010?
CVE-2021-38010 affects Google Chrome versions prior to 96.0.4664.45 and specific older versions of Chromium.
Is CVE-2021-38010 an issue for Debian users?
Yes, Debian users with affected Chromium versions prior to 90.0.4430.212-1~deb10u1 are impacted by CVE-2021-38010.
What impact does CVE-2021-38010 have on users?
CVE-2021-38010 allows attackers who have compromised the renderer process to bypass site isolation, potentially leading to unauthorized access to sensitive data.