CVE-2021-38017: Insufficient policy enforcement in iframe sandbox
Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-38017?
CVE-2021-38017 has a high severity level due to its potential to allow remote attackers to bypass security restrictions.
How do I fix CVE-2021-38017?
To fix CVE-2021-38017, upgrade Google Chrome to version 96.0.4664.45 or later.
What products are affected by CVE-2021-38017?
CVE-2021-38017 affects Google Chrome versions prior to 96.0.4664.45 and certain versions of the Chromium package on Debian.
What types of attacks can exploit CVE-2021-38017?
CVE-2021-38017 can be exploited through crafted HTML pages that bypass iframe sandbox navigation restrictions.
Is there a known fix for Chromium affected by CVE-2021-38017?
Yes, the affected versions of Chromium can be fixed by updating to the specified remedied versions for Debian.