QID 630795
Date Published: 2022-04-19
QID 630795: Google Chrome For Android Incorrect Authorization Vulnerability
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-38020 to address this issue and obtain more information.
Vendor References
- CVE-2021-38020 -
nvd.nist.gov/vuln/detail/CVE-2021-38020
CVEs related to QID 630795
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-38020 | Android |
|