Vulnerability CVE-2021-21136: Information

Description

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Published: Feb. 9, 2021
Modified: March 8, 2021
Error type identifier: CWE-346

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
      End excliding
      88.0.705.50