ZeroHour

CVE-2021-38000

KEV PoC mass1

Improper Input Validation in Google Chrome for Android Allows Forced URL Navigation

CISA: Google Chromium Intents Improper Input Validation Vulnerability

CVSS 3.1
6.1 medium
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2021-38000 is an insufficient input validation flaw in the Intents component of Google Chrome on Android (CWE-20/CWE-601), allowing a remote attacker to make the browser navigate to an arbitrary, attacker-chosen URL by luring the user to a crafted HTML page. It is essentially a forced-navigation/open-redirect bug: the user must interact with the malicious page (user interaction required), and the attacker gains limited confidentiality and integrity impact by steering the browser to a malicious URL, which is typically chained with other flaws. The bug was fixed in Chrome 95.0.4638.69 for Android, and the flaw is also tracked against Chromium packages distributed in Fedora and Debian. It carries a CVSS 3.1 score of 6.1 (medium) and an EPSS of 4.7% (91st percentile). Exploitation is confirmed in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and contemporaneous headlines describe Google patching actively exploited Chrome zero-days, with press reports linking Chrome zero-day attacks on Android users to Predator spyware campaigns.

What to do: Update Chrome on Android to version 95.0.4638.69 or later — since Chrome auto-updates, verify the installed version via Settings > About Chrome on managed and BYOD devices. Fedora and Debian users should install the current Chromium/Chrome security updates from their distribution. Inventory mobile fleets and internet-facing kiosk/device estates for Chrome builds below 95.0.4638.69 and treat user lures to crafted web pages as the primary delivery vector.

Affected
Google Chrome (Android)All versions prior to 95.0.4638.69
Fedora Project Fedora Linux (Chromium/Chrome package)Distro-packaged builds prior to the upstream fix (95.0.4638.69); exact Fedora package versions not specified in source data
Debian Linux (Chromium/Chrome package)Distro-packaged builds prior to the upstream fix (95.0.4638.69); exact Debian package versions not specified in source data
Estimated exposure
mass≈1 billion+ Chrome for Android users (Chrome is the dominant browser on Android's multi-billion-device install base) — Chrome for Android is the default or most widely used browser across Android's roughly 3 billion active devices, so the vulnerable pre-95.0.4638.69 install base at disclosure was plausibly on the order of a billion or more users.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

CISA Known Exploited Vulnerability
Affected
Google Chromium Intents
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraprojectdebian
Products
chrome, fedora, debian linux
Weakness
CWE-601, CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news