EXPOSURES › CVE-2021-38000
CVE-2021-38000
HIGH ⌖ ON CISA KEV · EXPLOITEDA Chromium input validation flaw allowed attackers to force browsers to navigate to malicious URLs via crafted HTML pages.
This improper input validation in Chromium's Intents feature let remote attackers redirect users to harmful sites without executing code, but it still represents a significant exposure for DIBs relying on Chromium-based browsers. The vulnerability was actively exploited in the wild (KEV), meaning organizations must ensure their browsers are patched and monitor for phishing campaigns leveraging this redirect capability. DIBs should verify their browser update policies are strict and consider additional endpoint protections to mitigate the risk of user-driven compromise.
Shame score — The flaw was actively exploited in the wild (KEV) and affected widely deployed Chromium-based browsers, indicating a failure to patch a known vulnerability before it was weaponized.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
| PRODUCT | STATUS |
|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) Google |
Authorized |
| Google Workspace Google |
Authorized |