Loading
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
Use CWE-601, Google vendor hub and Chrome product page to widen CVE-2021-38000 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-6920, CVE-2026-6919 and CVE-2026-6363 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.