First published: Fri Apr 06 2018(Updated: )
Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.
Credit: chrome-cve-admin@google.com Jun Kokatsu @shhnjk
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <91.0.4472.77 | 91.0.4472.77 |
Google Chrome (Trace Event) | <91.0.4472.77 | |
Fedora | =33 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30537 is classified as a high-severity vulnerability due to its ability to allow remote attackers to bypass cookie policy.
To fix CVE-2021-30537, users should update Google Chrome to version 91.0.4472.77 or later.
CVE-2021-30537 affects all versions of Google Chrome prior to 91.0.4472.77.
Yes, CVE-2021-30537 can impact web applications by allowing attackers to manipulate cookie policies.
CVE-2021-30537 can enable attackers to conduct session hijacking or impersonation attacks by bypassing cookie security measures.