{"cveID":"CVE-2021-38000","vendorProject":"Google","product":"Chromium Intents","vulnerabilityName":"Google Chromium Intents Improper Input Validation Vulnerability","dateAdded":"2021-11-03","shortDescription":"Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2021-11-17","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-38000","cwes":["CWE-20"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"mobile","cve":"CVE-2021-38000","technique":"T1660","technique_name_at_mapping":"Phishing","mapping_type":"exploitation_technique","capability_group":"input_validation","comments":"This zero-day vulnerability allows an adversary to redirect intent URLs and transfer execution to another application on the Android device. Reports indicate that threat actors have exploited the vulnerability by sending exploit links to targeted Android users via Android messages.","references":["https://issues.chromium.org/issues/40057279","https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2021/CVE-2021-38000.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"mobile","cve":"CVE-2021-38000","technique":"T1437","technique_name_at_mapping":"Application Layer Protocol","mapping_type":"primary_impact","capability_group":"input_validation","comments":"This zero-day vulnerability allows an adversary to redirect intent URLs and transfer execution to another application on the Android device. Reports indicate that threat actors have exploited the vulnerability by sending exploit links to targeted Android users via Android messages.","references":["https://issues.chromium.org/issues/40057279","https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2021/CVE-2021-38000.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"mobile","cve":"CVE-2021-38000","technique":"T1658","technique_name_at_mapping":"Exploitation for Client Execution","mapping_type":"primary_impact","capability_group":"input_validation","comments":"This zero-day vulnerability allows an adversary to redirect intent URLs and transfer execution to another application on the Android device. Reports indicate that threat actors have exploited the vulnerability by sending exploit links to targeted Android users via Android messages.","references":["https://issues.chromium.org/issues/40057279","https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2021/CVE-2021-38000.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1437","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Application Layer Protocol","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":false},{"id":"T1658","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Exploitation for Client Execution","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":false},{"id":"T1660","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Phishing","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":0,"has_detection_strategy":false}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["mobile"],"sigma_coverage":"n/a","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}