Vulnerability CVE-2021-37995: Information

Description

Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Published: Nov. 3, 2021
Modified: Feb. 28, 2022

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus95.0.4638.54-alt1124.0.6367.78-alt1ALT-PU-2021-3095-1287774Fixed
chromiump1096.0.4664.45-alt2.p10.1119.0.6045.159-alt0.p10.1ALT-PU-2021-3408-1289351Fixed
chromiump996.0.4664.45-alt2.p9.197.0.4692.99-alt0.p9.1ALT-PU-2021-3583-1291748Fixed
chromiumc10f196.0.4664.45-alt2.p10.1110.0.5481.177-alt1.p10.1ALT-PU-2021-3408-1289351Fixed
chromium-gostsisyphus96.0.4664.45-alt1121.0.6167.160-alt1ALT-PU-2021-3329-1290370Fixed
chromium-gostp1096.0.4664.45-alt2.p10.1110.0.5481.177-alt1.p10.1ALT-PU-2021-3431-1290499Fixed
chromium-gostp996.0.4664.45-alt2.p9.196.0.4664.45-alt2.p9.1ALT-PU-2021-3603-1291751Fixed
chromium-gostc10f196.0.4664.45-alt2.p10.1110.0.5481.177-alt1.p10.1ALT-PU-2021-3431-1290499Fixed
chromium-gostc9f296.0.4664.45-alt2.c9.196.0.4664.45-alt2.c9.1ALT-PU-2021-3436-1284092Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://crbug.com/1242315
  • Permissions Required
  • Vendor Advisory
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_19.html
  • Vendor Advisory
DSA-5046
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excliding
      95.0.4638.54

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*