ZeroHour

CVE-2021-30533

KEV PoC mass

PopupBlocker Policy Bypass in Google Chrome (CVE-2021-30553)

CISA: Google Chromium PopupBlocker Security Bypass Vulnerability

CVSS 3.1
6.5 medium
EPSS
17%p97
Published
()
KEV added
AI analysis

Google Chrome prior to 91.0.4472.77 contains a security bypass (CWE-863, incorrect authorization) in its PopupBlocker component, caused by insufficient enforcement of navigation policies. A remote attacker can trigger the flaw by luring a user to a page containing a crafted iframe, which bypasses the browser's navigation restrictions without requiring privileges or complex conditions. The gain is an integrity impact per the CVSS vector (C:N/I:H/A:N): the attacker can navigate or load content contrary to the enforced popup/navigation policy, though confidentiality and availability are not directly affected. Users running vulnerable versions of Google Chrome and Fedora's Chromium builds predating the fix are affected. The issue is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27, ransomware use unknown), indicating exploitation in the wild, and a public proof-of-concept reference exists in the Chromium bug tracker (crbug.com/1145553).

What to do: Update Google Chrome and any Chromium-based browsers to 91.0.4472.77 or later (verify via chrome://settings/help). On Fedora systems, apply the distribution's updated Chromium packages through dnf/update the OS per vendor instructions. CISA KEV listing requires federal agencies to complete this update by the assigned due date; defenders should confirm browser versions fleet-wide and watch for crafted-iframe navigation bypasses.

Affected
google chromeall versions prior to 91.0.4472.77
fedoraproject fedora (Chromium package)affected versions not specified in source data; Fedora Chromium builds based on upstream Chrome before the 91.0.4472.77 fix
Estimated exposure
mass≈3 billion Chrome users/devices worldwide (Chrome holds roughly 65% browser market share); only installs still running pre-91.0.4472.77 builds at disclosure… — Chrome is the world's dominant browser with an install base on the order of billions of users, and Fedora distributes the same vulnerable Chromium codebase, although Chrome's rapid auto-update mechanism means the currently vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.

CISA Known Exploited Vulnerability
Affected
Google Chromium PopupBlocker
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
googlefedoraproject
Products
chrome, fedora
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news