MEDIUM

CVE-2021-30533

Google Chrome 2021-06-07 CVSS v3.1
CVSS
6.5
KEV

Description

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.

Summary dbcve.org

The PopupBlocker component in Google Chrome prior to version 91.0.4472.77 had insufficient policy enforcement that could be bypassed using a crafted iframe. This allowed a remote attacker to circumvent navigation restrictions and potentially open unauthorized popups or perform unintended navigation actions.

Mitigation

Update Google Chrome to version 91.0.4472.77 or later. In enterprise environments, ensure automated patch deployment reaches all client systems.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

16.61%
Probability of exploitation in next 30 days
96.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE