Coverage › CVE-2021-38000
CVE-2021-38000 Mapped Mobile only
Google Chromium Intents Improper Input Validation Vulnerability
- Vendor / product
- Google — Chromium Intents
- Description (CISA)
- Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
- Added to KEV
- 2021-11-03
- Due date
- 2021-11-17
- Required action
- Apply updates per vendor instructions.
- Known ransomware use
- Unknown
- CWE
- CWE-20
- CISA notes
- https://nvd.nist.gov/vuln/detail/CVE-2021-38000
- Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such. Mappings marked mobile refer to ATT&CK Mobile; this site traverses the Enterprise bundle only and shows no detection chain for them.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1660 Phishingmobile | exploitation technique | This zero-day vulnerability allows an adversary to redirect intent URLs and transfer execution to another application on the Android device. Reports indicate that threat actors have exploited the vulnerability by sending exploit links to targeted Android users via Android messages. ref 1 · ref 2 |
not checked (Mobile) |
| T1437 Application Layer Protocolmobile | primary impact | This zero-day vulnerability allows an adversary to redirect intent URLs and transfer execution to another application on the Android device. Reports indicate that threat actors have exploited the vulnerability by sending exploit links to targeted Android users via Android messages. ref 1 · ref 2 |
not checked (Mobile) |
| T1658 Exploitation for Client Executionmobile | primary impact | This zero-day vulnerability allows an adversary to redirect intent URLs and transfer execution to another application on the Android device. Reports indicate that threat actors have exploited the vulnerability by sending exploit links to targeted Android users via Android messages. ref 1 · ref 2 |
not checked (Mobile) |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
No live Enterprise technique to traverse.