Junglewise Threat Intelligence

CVE-2021-30533: Google Chromium PopupBlocker Security Bypass Vulnerability

CVE-2021-30533 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-06-27

Technologies: Google Chrome, Microsoft Edge. Vendors: Google, Opera, Microsoft.

Executive brief

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This flaw enables attackers to circumvent intended security controls in browsers based on Chromium.

Affected products

  • Google Chrome prior to 91.0.4472.77
  • Microsoft Edge
  • Opera Opera
  • Fedora Project Fedora 33, 34

Timeline

  • 2021-05-25: patched: Stable channel update for desktop released.
  • 2022-06-27: disclosed: NVD publication date.
  • 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
  • exploited: Reported as exploited in the wild.