CVE-2021-30533: Google Chromium PopupBlocker Security Bypass Vulnerability
Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Other sources
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 91.0.4472.77
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30521
- CVE-2021-30522
- CVE-2021-30523
- CVE-2021-30524
- CVE-2021-30525
- CVE-2021-30526
- CVE-2021-30527
- CVE-2021-30528
- CVE-2021-4322
- CVE-2021-30529
- CVE-2021-30530
- CVE-2021-30531
- CVE-2021-30532
- CVE-2021-30534
- CVE-2021-30535
- CVE-2021-30542
- CVE-2021-30543
- CVE-2021-30558
- CVE-2021-30536
- CVE-2021-30537
- CVE-2021-30538
- CVE-2021-30539
- CVE-2021-30540
- CVE-2021-4321
Frequently Asked Questions
What is CVE-2021-30533?
CVE-2021-30533 is a security bypass vulnerability affecting Google Chromium.
What is the severity of CVE-2021-30533?
CVE-2021-30533 has a severity level of 6.5 (Medium).
Which software is affected by CVE-2021-30533?
CVE-2021-30533 affects web browsers using Chromium, such as Google Chrome and Microsoft Edge.
How can an attacker exploit CVE-2021-30533?
CVE-2021-30533 allows an attacker to remotely bypass security mechanisms in the PopupBlocker for Chromium.
Is there a fix available for CVE-2021-30533?
Yes, a patch for CVE-2021-30533 has been released. It is recommended to update your affected software to the latest version.