Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html | release notes |
https://crbug.com/1249962 | issue tracking exploit |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W46HRT2UVHWSLZB6JZHQF6JNQWKV744/ | release notes vendor advisory |
https://www.debian.org/security/2022/dsa-5046 | mailing list third party advisory vendor advisory |