Spoofing attack in Google Chrome - CVE-2021-30540
Published: May 25, 2021 / Updated: May 25, 2021
Vulnerability identifier: #VU53561
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30540
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation of user-supplied input in payments in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and spoof web page content.
Affected software
Google Chrome
Microsoft Edge
Gentoo Linux
Arch Linux
Fedora
chromium
Microsoft Edge
Gentoo Linux
Arch Linux
Fedora
chromium
How to mitigate CVE-2021-30540
Update to version 91.0.4472.77.
Google Chrome - update to 91.0.4472.77
Microsoft Edge - update to 91.0.864.37
chromium - addressed in versions 91.0.4472.114-1.el8, 91.0.4472.114-1.fc33, 91.0.4472.114-1.fc34, 91.0.4472.114-2.el8, 91.0.4472.114-2.fc33, 91.0.4472.164-1.el8
Microsoft Edge - update to 91.0.864.37
chromium - addressed in versions 91.0.4472.114-1.el8, 91.0.4472.114-1.fc33, 91.0.4472.114-1.fc34, 91.0.4472.114-2.el8, 91.0.4472.114-2.fc33, 91.0.4472.164-1.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- Multiple vulnerabilities in Microsoft Edge (Chromium-based)
- Arch Linux update for chromium
- Gentoo update for Chromium, Google Chrome
- Fedora 34 update for chromium
- Fedora 33 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 33 update for chromium
- Fedora EPEL 8 update for chromium