First published: Fri Apr 30 2021(Updated: )
Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Credit: chrome-cve-admin@google.com Abdulrahman Alqabandi Microsoft Browser Vulnerability Research
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <92.0.4515.107 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Google Chrome | <92.0.4515.107 | 92.0.4515.107 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-30587 is a vulnerability in the Compositing implementation in Google Chrome prior to version 92.0.4515.107.
CVE-2021-30587 allows a remote attacker to potentially spoof the contents of the Omnibox (URL bar) by using a crafted HTML page.
Google Chrome versions prior to 92.0.4515.107 are affected by CVE-2021-30587.
CVE-2021-30587 has a severity rating of medium with a CVSS score of 4.3.
To fix the CVE-2021-30587 vulnerability, update Google Chrome to version 92.0.4515.107 or later.