Executive brief
Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This flaw enables attackers to circumvent intended security controls in browsers based on Chromium.
Affected products
- Google Chrome prior to 91.0.4472.77
- Microsoft Edge
- Opera Opera
- Fedora Project Fedora 33, 34
Timeline
- 2021-05-25: patched: Stable channel update for desktop released.
- 2022-06-27: disclosed: NVD publication date.
- 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
- exploited: Reported as exploited in the wild.