CVE-2021-30533
KEV PoC massPopupBlocker Policy Bypass in Google Chrome (CVE-2021-30553)
CISA: Google Chromium PopupBlocker Security Bypass Vulnerability
Google Chrome prior to 91.0.4472.77 contains a security bypass (CWE-863, incorrect authorization) in its PopupBlocker component, caused by insufficient enforcement of navigation policies. A remote attacker can trigger the flaw by luring a user to a page containing a crafted iframe, which bypasses the browser's navigation restrictions without requiring privileges or complex conditions. The gain is an integrity impact per the CVSS vector (C:N/I:H/A:N): the attacker can navigate or load content contrary to the enforced popup/navigation policy, though confidentiality and availability are not directly affected. Users running vulnerable versions of Google Chrome and Fedora's Chromium builds predating the fix are affected. The issue is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27, ransomware use unknown), indicating exploitation in the wild, and a public proof-of-concept reference exists in the Chromium bug tracker (crbug.com/1145553).
What to do: Update Google Chrome and any Chromium-based browsers to 91.0.4472.77 or later (verify via chrome://settings/help). On Fedora systems, apply the distribution's updated Chromium packages through dnf/update the OS per vendor instructions. CISA KEV listing requires federal agencies to complete this update by the assigned due date; defenders should confirm browser versions fleet-wide and watch for crafted-iframe navigation bypasses.
| google chrome | all versions prior to 91.0.4472.77 |
| fedoraproject fedora (Chromium package) | affected versions not specified in source data; Fedora Chromium builds based on upstream Chrome before the 91.0.4472.77 fix |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
- Affected
- Google Chromium PopupBlocker
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googlefedoraproject
- Products
- chrome, fedora
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N