CVE-2021-4324: Insufficient policy enforcement in Google Update
Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file. (Chromium security severity: Medium)
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-4324?
The severity of CVE-2021-4324 is medium with a severity value of 6.5.
How does CVE-2021-4324 impact Google Chrome?
CVE-2021-4324 allows a remote attacker to read arbitrary files via a malicious file in Google Chrome prior to version 90.0.4430.93.
What is the affected software for CVE-2021-4324?
The affected software for CVE-2021-4324 is Google Chrome prior to version 90.0.4430.93.
How can I fix the vulnerability CVE-2021-4324?
To fix CVE-2021-4324, update Google Chrome to version 90.0.4430.93 or later.
Are there any references for CVE-2021-4324?
Yes, you can find more information about CVE-2021-4324 at the following references: [Reference 1](https://crbug.com/1193233), [Reference 2](https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_26.html), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PQKT7EGDD2P3L7S3NXEDDRCPK4NNZNWJ/)