⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..
CVE-2021-38000 — Open Redirect in Google Chrome
Severity
6.1MEDIUMNVD
OSV7.8
EPSS
4.5%
top 10.86%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
KEV addedNov 3
KEV dueNov 17
PublishedNov 23
Latest updateDec 3
CISA Required Action: Apply updates per vendor instructions.
Description
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages7 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 34
🔴Vulnerability Details
8OSV▶
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities↗2025-07-08
GHSA▶
GHSA-xrj7-4gfh-q9h7: Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95↗2021-11-24
OSV▶
CVE-2021-38000: Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95↗2021-11-23
📋Vendor Advisories
4Debian▶
CVE-2021-38000: chromium - Insufficient validation of untrusted input in Intents in Google Chrome on Androi...↗2021