Skip to main content
Mallory
MediumCISA KEVExploited in the wildPublic exploit

Google Chrome PopupBlocker navigation restriction bypass

IdentifiersCVE-2021-30533CWE-863· Incorrect Authorization

CVE-2021-30533 is an insufficient policy enforcement flaw in the PopupBlocker component of Google Chrome and other Chromium-based browsers. In versions prior to 91.0.4472.77, a remote attacker can use a crafted iframe to bypass browser navigation restrictions that should be enforced by PopupBlocker. The issue is described by Google as insufficient policy enforcement, and supporting sources map it to CWE-863. Public reporting also ties the bug to malvertising activity that abused iframe-based techniques to evade browser protections and trigger unauthorized navigations or redirects.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to bypass intended browser navigation restrictions, enabling unauthorized or unexpected navigations/redirects in the victim's browser session. The primary security impact is integrity-related rather than direct code execution: an attacker can force or facilitate navigation behavior that the browser should have blocked, which can be leveraged in malvertising, redirect chains, delivery of unwanted or malicious content, and related social-engineering workflows. Reported scoring indicates high integrity impact with no direct confidentiality or availability impact from this flaw alone.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by limiting use of untrusted websites and ad-driven content, especially where malicious iframes or redirect chains may be encountered. Employ least-privilege user contexts to reduce downstream impact, use browser and enterprise controls that restrict unwanted popups/redirects where available, and consider ad/malvertising filtering or isolation controls. User awareness measures around untrusted links and websites may also reduce exploitation opportunities, but patching is the primary mitigation.

Remediation

Patch, then assume compromise.

Update Google Chrome and affected Chromium-based browsers to version 91.0.4472.77 or later, or to the vendor-fixed package versions for downstream distributions. The content specifically references Google’s stable channel fix and downstream fixes such as Fedora chromium 91.0.4472.114 packages and SUSE/openSUSE package updates. Apply vendor updates per vendor instructions, including any Chromium, Chrome, WebEngine, or browser package updates that incorporate the upstream fix.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Fedora ProjectFedoraoperating_system
GoogleChromeapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.