CVE-2021-30533mediumunder attackCWE-863

CVE-2021-30533: medium-severity vulnerability in Google Chrome

Published · Updated

48Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Attendcvss 6.5epss 17%
from disclosure to weapon
Published on NVDJun 7
CISA KEV+385d
exploitation probability
17%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Action required by CISAfederal deadline: 2022-07-18

Apply updates per vendor instructions.

In short

Google Chrome's popup blocker wasn't properly enforced, allowing attackers to bypass navigation restrictions through a specially crafted iframe. This could redirect users to unwanted websites despite the popup blocker being enabled.

Technical detail

Insufficient policy enforcement in Chrome's PopupBlocker allowed a remote attacker to bypass navigation restrictions by crafting a malicious iframe. The vulnerability required user interaction with a specially designed web page and affected versions prior to 91.0.4472.77; impact was navigation restriction bypass potentially leading to unwanted redirects or malicious page loads.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
Google · Chrome