PT-2021-5566 · Google+2 · Google Chrome+2

Alison Huffman

·

Published

2021-05-16

·

Updated

2024-06-15

·

CVE-2021-30507

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome on Android versions prior to 90.0.4430.212
Description The issue is related to an inappropriate implementation in the offline mode of Google Chrome, allowing a remote attacker who has compromised the renderer process to bypass site isolation. This can be achieved via a crafted HTML page. The vulnerability is also related to the inclusion of features from an untrusted controlled area, which can be exploited by a remote attacker to bypass existing security restrictions using a specially crafted HTML page.
Recommendations For Google Chrome on Android versions prior to 90.0.4430.212, update to version 90.0.4430.212 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06422
CVE-2021-30507
DSA-4917-1
OPENSUSE-SU-2021:0742-1
OPENSUSE-SU-2021:0762-1
OPENSUSE-SU-2021:0828-1
OPENSUSE-SU-2021:0829-1
OPENSUSE-SU-2021_0742-1
OPENSUSE-SU-2021_0762-1
OPENSUSE-SU-2021_0828-1
OPENSUSE-SU-2021_0829-1
OPENSUSE-SU-2022:0110-1
OPENSUSE-SU-2022_0110-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1

Affected Products

Astra Linux
Google Chrome
Suse