MEDIUM
CVE-2021-30533
CVSS
6.5
KEV
Description
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
Summary dbcve.org
The PopupBlocker component in Google Chrome prior to version 91.0.4472.77 had insufficient policy enforcement that could be bypassed using a crafted iframe. This allowed a remote attacker to circumvent navigation restrictions and potentially open unauthorized popups or perform unintended navigation actions.
Mitigation
Update Google Chrome to version 91.0.4472.77 or later. In enterprise environments, ensure automated patch deployment reaches all client systems.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
16.61%
Probability of exploitation in next 30 days
96.9th percentile
References
https://chromereleases.googleblog.com/2021/05/stable-channel-update-for-desktop_25.html
Release Notes, Vendor Advisory
https://crbug.com/1145553
Exploit, Issue Tracking, Patch, Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ETMZL6IHCTCTREEL434BQ4THQ7EOHJ43/
Mailing List, Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAT6EOXVQFE6JFMFQF4IKAOUQSHMHL54/
Mailing List, Release Notes
https://security.gentoo.org/glsa/202107-06
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-30533
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.