First published: Wed Jul 22 2020(Updated: )
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.
Credit: chrome-cve-admin@google.com chrome-cve-admin@google.com David Erceg
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <88.0.4324.96 | |
Microsoft Edge Chromium | <88.0.705.50 | |
Google Chrome | <88.0.4324.96 | 88.0.4324.96 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID of this security issue is CVE-2021-21126.
The severity of CVE-2021-21126 is medium (6.5).
Google Chrome versions prior to 88.0.4324.96 and Microsoft Edge Chromium versions prior to 88.0.705.50 are affected by CVE-2021-21126.
CVE-2021-21126 allows a remote attacker to bypass site isolation through a crafted Chrome Extension.
Update Google Chrome to version 88.0.4324.96 or later, and update Microsoft Edge Chromium to version 88.0.705.50 or later to fix CVE-2021-21126.