First published: Wed Aug 12 2020(Updated: )
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Credit: chrome-cve-admin@google.com Philip Papurt
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <91.0.4472.77 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Google Chrome | <91.0.4472.77 | 91.0.4472.77 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30531 is categorized as a high-severity vulnerability due to its ability to allow remote attackers to bypass content security policies.
To fix CVE-2021-30531, users should update Google Chrome to version 91.0.4472.77 or later.
CVE-2021-30531 affects all versions of Google Chrome prior to 91.0.4472.77.
Yes, Fedora 33 and 34 are affected by CVE-2021-30531 if running an outdated version of Google Chrome.
CVE-2021-30531 allows remote attackers to execute arbitrary scripts by bypassing the content security policy through crafted HTML pages.