Improper enforcement of behavioral workflow in Google Chromium - CVE-2021-38004
Published: January 17, 2022
Vulnerability identifier: #VU59668
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38004
CWE-ID: CWE-841
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient policy enforcement in Autofill. A remote attacker can create a specially crafted web page, trick the victim into visiting it and bypass implemented security restrictions.
Affected software
Google Chromium
Arch Linux
Fedora
vivaldi
opera
chromium
chromium (Debian package)
Arch Linux
Fedora
vivaldi
opera
chromium
chromium (Debian package)
How to mitigate CVE-2021-38004
Update to version 95.0.4638.69.
Google Chromium - update to 95.0.4638.69
vivaldi - update to 5.0.2497.24-1
opera - update to 81.0.4196.54-1
chromium - addressed in versions 96.0.4664.110-2.el8, 96.0.4664.110-2.fc34, 96.0.4664.110-2.fc35, 96.0.4664.110-3.fc34, 96.0.4664.110-3.fc35
chromium (Debian package) - update to 97.0.4692.71-0.1~deb11u1
vivaldi - update to 5.0.2497.24-1
opera - update to 81.0.4196.54-1
chromium - addressed in versions 96.0.4664.110-2.el8, 96.0.4664.110-2.fc34, 96.0.4664.110-2.fc35, 96.0.4664.110-3.fc34, 96.0.4664.110-3.fc35
chromium (Debian package) - update to 97.0.4692.71-0.1~deb11u1