CISA Known Exploited Vulnerability

CVE-2021-30533

Google · Chromium PopupBlocker

Google Chromium PopupBlocker Security Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-863
Ransomware Unknown

CISA description

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required action

Apply updates per vendor instructions.