First published: Tue Oct 05 2021(Updated: )
Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Credit: chrome-cve-admin@google.com NDevTK
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | <=90.0.4430.212-1~deb10u1 | 116.0.5845.180-1~deb11u1 118.0.5993.70-1~deb11u1 116.0.5845.180-1~deb12u1 118.0.5993.70-1~deb12u1 118.0.5993.70-1 |
Google Chrome | <96.0.4664.45 | 96.0.4664.45 |
Google Chrome | <96.0.4664.45 | |
Fedora | =34 | |
Debian | =10.0 | |
Debian | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-38017 has a high severity level due to its potential to allow remote attackers to bypass security restrictions.
To fix CVE-2021-38017, upgrade Google Chrome to version 96.0.4664.45 or later.
CVE-2021-38017 affects Google Chrome versions prior to 96.0.4664.45 and certain versions of the Chromium package on Debian.
CVE-2021-38017 can be exploited through crafted HTML pages that bypass iframe sandbox navigation restrictions.
Yes, the affected versions of Chromium can be fixed by updating to the specified remedied versions for Debian.