Skip to content
COOEY

EXPOSURES › CVE-2021-30533

CVE-2021-30533

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-06-27 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-30533 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

A Chromium PopupBlocker vulnerability allowed attackers to bypass navigation restrictions via crafted iframes, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.

An insufficient policy enforcement flaw in the Chromium PopupBlocker enabled attackers to bypass navigation restrictions, potentially leading to malicious website access and data compromise. DIB organizations using Chromium-based browsers must promptly patch and review navigation policies to mitigate this risk and maintain NIST 800-171 compliance. This highlights the importance of timely patching and third-party component risk management.

Shame score — The vulnerability's active exploitation and broad impact across multiple browsers demonstrates a significant policy enforcement failure with avoidable consequences.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized