⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..

CVE-2021-38000Open Redirect in Google Chrome

Severity
6.1MEDIUMNVD
OSV7.8
EPSS
4.5%
top 10.86%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
KEV addedNov 3
KEV dueNov 17
PublishedNov 23
Latest updateDec 3
CISA Required Action: Apply updates per vendor instructions.

Description

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

CVEListV5google/chromeunspecified95.0.4638.69
NVDgoogle/chrome< 95.0.4638.69
debiandebian/chromium< chromium 97.0.4692.71-0.1 (bookworm)
Debianchromium/chromium< 97.0.4692.71-0.1~deb11u1+3

Also affects: Debian Linux 10.0, 11.0, Fedora 34

🔴Vulnerability Details

8
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2025-07-08
OSV
linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips vulnerabilities2025-07-08
Project0
The More You Know, The More You Know You Don’t Know - Project Zero2022-04-01
GHSA
GHSA-xrj7-4gfh-q9h7: Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 952021-11-24
OSV
CVE-2021-38000: Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 952021-11-23

📋Vendor Advisories

4
CISA
Google Chromium Intents Improper Input Validation Vulnerability2021-11-03
Chrome
Stable Channel Update for Desktop: CVE-2021-379992021-10-28
Microsoft
Chromium: CVE-2021-38000 Insufficient validation of untrusted input in Intents2021-10-12
Debian
CVE-2021-38000: chromium - Insufficient validation of untrusted input in Intents in Google Chrome on Androi...2021

🕵️Threat Intelligence

7
Mandiant
Intellexa’s Prolific Zero-Day Exploits Continue2025-12-03
Mandiant
Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue2025-12-03
Talos
Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware2023-05-25
Talos
Mercenary mayhem: A technical analysis of Intellexa&#x27;s PREDATOR spyware2023-05-25
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys2022-02-23

📄Research Papers

1
arXiv
A Relevance Model for Threat-Centric Ranking of Cybersecurity Vulnerabilities2024-06-09