CVE-2021-30630: Inappropriate implementation in Blink
Published Aug 30, 2021
·Updated
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Credit
SorryMybad@@S0rryMybad(Kunlun Lab)
Affected Software
4 affected componentsFixes available
Google Chrome<93.0.4577.82
93.0.4577.82
Google Chrome<93.0.4577.82
fedoraproject fedora=33
fedoraproject fedora=35
Event History
Aug 30, 2021
CVE Published
12:00 AM
Oct 8, 2021
CVE Published
via MITRE·08:50 PM
Data Sourced
via MITRE·08:50 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2021-30630?
CVE-2021-30630 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2021-30630?
To fix CVE-2021-30630, users need to update Google Chrome to version 93.0.4577.82 or later.
3
What causes CVE-2021-30630?
CVE-2021-30630 is caused by an inappropriate implementation in Blink within Google Chrome.
4
Who is affected by CVE-2021-30630?
CVE-2021-30630 affects users of Google Chrome versions prior to 93.0.4577.82 and specific Fedora versions.
5
What type of attack does CVE-2021-30630 enable?
CVE-2021-30630 enables a remote attacker to leak cross-origin data via a crafted HTML page.