First published: Wed Mar 03 2021(Updated: )
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Credit: chrome-cve-admin@google.com @retsew0x01
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <91.0.4472.77 | 91.0.4472.77 |
Google Chrome (Trace Event) | <91.0.4472.77 | |
Fedora | =33 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30540 has a medium severity score due to its potential for domain spoofing.
Updating Google Chrome to version 91.0.4472.77 or later resolves the vulnerability in CVE-2021-30540.
CVE-2021-30540 is classified as a security UI vulnerability allowing domain spoofing.
CVE-2021-30540 affects Google Chrome on Android prior to version 91.0.4472.77 as well as Fedora versions 33 and 34.
CVE-2021-30540 allows a remote attacker to perform domain spoofing through a crafted HTML page.