Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html | release notes |
https://crbug.com/1249962 | exploit issue tracking |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W46HRT2UVHWSLZB6JZHQF6JNQWKV744/ | vendor advisory release notes |
https://www.debian.org/security/2022/dsa-5046 | third party advisory vendor advisory mailing list |