Skip to content
COOEY

EXPOSURES › CVE-2021-38000

CVE-2021-38000

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-38000 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

A Chromium input validation flaw allowed attackers to force browsers to navigate to malicious URLs via crafted HTML pages.

This improper input validation in Chromium's Intents feature let remote attackers redirect users to harmful sites without executing code, but it still represents a significant exposure for DIBs relying on Chromium-based browsers. The vulnerability was actively exploited in the wild (KEV), meaning organizations must ensure their browsers are patched and monitor for phishing campaigns leveraging this redirect capability. DIBs should verify their browser update policies are strict and consider additional endpoint protections to mitigate the risk of user-driven compromise.

Shame score — The flaw was actively exploited in the wild (KEV) and affected widely deployed Chromium-based browsers, indicating a failure to patch a known vulnerability before it was weaponized.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of the vulnerability and its potential impact, with no indication of praise or mitigation efforts by Google.
cooey ↗ severe-fallout -0.70
Neutral reporting, but highlighting the broad impact.
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
app.opencve.io ↗ severe-fallout +0.00
No sentiment expressed.
chromereleases.googleblog.com ↗ severe-fallout +0.00
No sentiment expressed.
www.cvefind.com ↗ severe-fallout +0.00
No sentiment expressed.
cvefeed.io ↗ severe-fallout +0.00
No sentiment expressed.
www.hipaajournal.com ↗ severe-fallout +0.00
No sentiment expressed.
cvedb.shodan.io ↗ severe-fallout +0.00
No sentiment expressed.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized