CVE-2021-38015: Inappropriate implementation in input
Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-38015?
CVE-2021-38015 has a medium severity rating as it involves the inappropriate implementation of input handling in Google Chrome.
How do I fix CVE-2021-38015?
To mitigate CVE-2021-38015, update Google Chrome to version 96.0.4664.45 or later.
Which software versions are affected by CVE-2021-38015?
CVE-2021-38015 affects Google Chrome versions prior to 96.0.4664.45 and several Debian Chromium packages up to version 90.0.4430.212-1.
Can malicious extensions exploit CVE-2021-38015?
Yes, attackers can exploit CVE-2021-38015 by convincing users to install malicious Chrome extensions that bypass navigation restrictions.
What platforms are impacted by CVE-2021-38015?
CVE-2021-38015 impacts users on platforms such as Google Chrome, Debian, and Fedora operating systems.