← Back to browse · API

CVE-2021-38000

Severity
MEDIUM
CVSS
6.1
EPSS
0.04485
Risk score
50.97
CISA KEV
Yes
PoC
No
Published
2021-11-23
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-24473, GHSA-XRJ7-4GFH-Q9H7
Products
Google:Chrome unspecified <95.0.4638.69, Google:Chromium Intents
Sources
euvd EUVD-2021-24473
cisa.gov CVE-2021-38000

Description

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

References