CVE-2021-30533: medium-severity vulnerability in Google Chrome
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Google Chrome's popup blocker wasn't properly enforced, allowing attackers to bypass navigation restrictions through a specially crafted iframe. This could redirect users to unwanted websites despite the popup blocker being enabled.
Insufficient policy enforcement in Chrome's PopupBlocker allowed a remote attacker to bypass navigation restrictions by crafting a malicious iframe. The vulnerability required user interaction with a specially designed web page and affected versions prior to 91.0.4472.77; impact was navigation restriction bypass potentially leading to unwanted redirects or malicious page loads.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.