CVE-2021-4321: Policy bypass in Blink
Published Dec 27, 2020
·Updated
Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Credit
Austin Williams
Affected Software
2 affected componentsFixes available
Google Chrome<91.0.4472.77
91.0.4472.77
Google Chrome<91.0.4472.77
Event History
Dec 27, 2020
CVE Published
12:00 AM
Jul 28, 2023
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30521
- CVE-2021-30522
- CVE-2021-30523
- CVE-2021-30524
- CVE-2021-30525
- CVE-2021-30526
- CVE-2021-30527
- CVE-2021-30528
- CVE-2021-4322
- CVE-2021-30529
- CVE-2021-30530
- CVE-2021-30531
- CVE-2021-30532
- CVE-2021-30533
- CVE-2021-30534
- CVE-2021-30535
- CVE-2021-30542
- CVE-2021-30543
- CVE-2021-30558
- CVE-2021-30536
- CVE-2021-30537
- CVE-2021-30538
- CVE-2021-30539
- CVE-2021-30540
Frequently Asked Questions
1
What is the vulnerability ID of this policy bypass in Blink in Google Chrome?
The vulnerability ID is CVE-2021-4321.
2
What is the severity of CVE-2021-4321?
The severity of CVE-2021-4321 is Medium (4.3).
3
How does this vulnerability in Blink in Google Chrome allow a policy bypass?
This vulnerability allows a remote attacker to bypass content security policy via a crafted HTML page.
4
Which versions of Google Chrome are affected by CVE-2021-4321?
Google Chrome versions prior to 91.0.4472.77 are affected.
5
How can I fix CVE-2021-4321?
To fix CVE-2021-4321, update your Google Chrome browser to version 91.0.4472.77 or later.