Permissions, Privileges, and Access Controls in Google Chrome - CVE-2021-21136

 

Permissions, Privileges, and Access Controls in Google Chrome - CVE-2021-21136

Published: January 19, 2021 / Updated: January 19, 2021


Vulnerability identifier: #VU49714
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21136
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient policy enforcement in WebView in Google Chrome. A remote attacker can trick the victim to visit a specially crafted website, bypass implemented security measures and gain access to sensitive information.


Affected software

Google Chrome
Microsoft Edge
Arch Linux
Gentoo Linux
Fedora
EMC Integrated Data Protection Appliance
chromium (Debian package)
chromium
Dell PowerEdge BIOS 15G
Dell PowerEdge BIOS 14G
Dell PowerEdge BIOS 13G
VxFlex ESXi
PowerProtect Data Domain

How to mitigate CVE-2021-21136

Update to version 88.0.4324.96.

Google Chrome - update to 88.0.4324.96
chromium (Debian package) - update to 88.0.4324.146-1~deb10u1
Dell PowerEdge BIOS 15G - update to 1.6.5
Dell PowerEdge BIOS 14G - update to 2.14.2
Dell PowerEdge BIOS 13G - update to 2.15.0
VxFlex ESXi - update to 6.7 P07
PowerProtect Data Domain - addressed in versions 7.7.4, 7.10.0.0
Microsoft Edge - update to 88.0.705.50
chromium - addressed in versions 88.0.4324.96-1.el7, 88.0.4324.96-1.el8, 88.0.4324.96-1.fc32, 88.0.4324.96-1.fc33, 88.0.4324.150-1.el7, 88.0.4324.150-1.el8

External References

Related Security Bulletins