CVE-2021-38000

CVE Published 2021-11-23
Related CWE(s) CWE-20: Improper Input Validation, CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Related Vendor(s) debian, google, fedoraproject
Related Product(s) debian_linux, chrome, fedora
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 6.1 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References