Improper access control in Google Chromium - CVE-2021-30617

 

Improper access control in Google Chromium - CVE-2021-30617

Published: August 31, 2021


Vulnerability identifier: #VU56208
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30617
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper access restrictions in Blink. A remote attacker can create a specially crafted web page, trick the victim into visiting it, bypass implemented security restrictions and gain unauthorized access to sensitive information.


Affected software

Google Chromium
Google Chrome
Microsoft Edge
Gentoo Linux
Fedora
chromium

How to mitigate CVE-2021-30617

Update to version 93.0.4577.63.

Google Chromium - update to 93.0.4577.63
Google Chrome - update to 93.0.4577.63
Microsoft Edge - update to 93.0.961.38
chromium - addressed in versions 93.0.4577.63-1.el8, 93.0.4577.63-1.fc33, 93.0.4577.63-1.fc34, 93.0.4577.63-1.fc35

External References

Related Security Bulletins