CVE-2021-38000KEV · OVERDUE

Google Chromium Intents Improper Input Validation Vulnerability

Medium · published November 23, 2021

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 6.1. It is confirmed in active exploitation. It sits in the 91.1th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
6.1
EPSS
5%
Percentile
91.1
In the wild
Confirmed
What it is

⚠️ A crafty crafted HTML page is all it takes to send users to a malicious URL! This flaw in Google Chrome on Android before version 95.0.4638.69 opens up some sneaky possibilities for attackers. 🔥 Think of it like a restaurant menu that allows you to order dishes that aren't even on the menu — anyone can just call out whatever they want. If the restaurant staff isn't trained to double-check the orders, it could lead to some very unpleasant meals! An attacker could easily lure users to click on a malicious link, leading them to dangerous sites that can steal personal information or install malware. This vulnerability paves the way for phishing attacks, where the unsuspecting user might unknowingly hand over their sensitive data. 😱

Put simply

Think of it like a restaurant menu that allows you to order dishes that aren't even on the menu — anyone can just call out whatever they want. If the restaurant staff isn't trained to double-check the orders, it could lead to some very unpleasant meals! This vulnerability arises from insufficient validation of untrusted input within Intents in Google Chrome, allowing remote attackers to redirect users to arbitrary URLs through specially crafted HTML pages.

What to do

An attacker could easily lure users to click on a malicious link, leading them to dangerous sites that can steal personal information or install malware. This vulnerability paves the way for phishing attacks, where the unsuspecting user might unknowingly hand over their sensitive data. 😱 To protect yourself, update Google Chrome on Android to version 95.0.4638.69 or later immediately. It's crucial to stay vigilant and avoid clicking on suspicious links or visiting unsecured websites to minimize risk. 🛡️ You’ve got this! By following these steps, you're on your way to securing your browsing experience. 🚀

The record
Technical detail
CVSS v3.1
6.1 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.04653 · 91.1th percentile
Published
2021-11-23T21:30Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 23 NOV 21:30Z
    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a…
    cvelistv5
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev