LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-38000: Google Chromium Intents Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-38000 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could…

CVE-2021-38000 is an improper input validation weakness in Google Chromium Intents. A remote attacker can use a crafted HTML page to force the browser to navigate to a malicious URL. Because many browsers are built on Chromium, the issue can affect Google Chrome, Microsoft Edge, Opera, and other Chromium-based products. Teams should treat it as a browser-level risk that can lead users to attacker-controlled sites.

CISA notes that the required action is to apply updates per vendor instructions. Ransomware use is not documented for this CVE. Confirm exact affected builds and fixed releases against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). Chromium Intents handling fails to adequately validate certain input, so a malicious page can influence navigation decisions that should be constrained. In practical terms, an attacker who can get a user to load crafted HTML can cause the browser to open or redirect to a URL of the attacker’s choosing.

This is not a remote code execution flaw by itself; it is a navigation/control issue. The impact depends on what the malicious URL delivers—phishing, further browser exploits, or social-engineering payloads. Specific exploit mechanics beyond the CISA description are not provided here; treat any public proof-of-concept claims cautiously and verify against official advisories.

Am I affected? How to find it in your systems

Chromium-based browsers are common on endpoints, VDI images, kiosks, and developer workstations. Inventory every browser that embeds or is derived from Chromium, including Google Chrome, Microsoft Edge, Opera, and any internal or third-party Chromium shells.

If your scanners only report “Chrome” or “Edge” generically, drill into the precise channel (stable/beta/dev) and build number. Confirm findings against each vendor’s advisory.

How to remediate

Patch first. Apply the vendor updates that address CVE-2021-38000 for every Chromium-based browser in your environment, following the instructions in each vendor’s security bulletin. CISA’s required action is exactly that: apply updates per vendor instructions.

Re-scan after deployment to confirm the vulnerable component is no longer present.

If you can't patch immediately

Reduce likelihood and impact until updates can be applied.

These steps do not replace the vendor patch. Schedule the update as soon as operationally feasible.

If your data may have been exposed

Actively exploited browser vulnerabilities can be an entry point to phishing, credential theft, or follow-on compromise even when ransomware use is not documented for the specific CVE. If you suspect users were steered to malicious URLs, reset credentials for affected accounts, review access logs for anomalous logins, and follow your incident-response process for potential browser-based intrusion.

You can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal data have appeared in prior incidents, then take appropriate containment and monitoring steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium Intents
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities