CVE-2021-37999 PUBLISHED

Reported by Chrome · Published November 23, 2021

Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.

Affected Products

VendorProductVersions
GoogleChromeunspecified
GoogleChromeunspecified

Timeline

References

Open in Interactive Console →