
Cloud Vulnerability DB
A community-led vulnerabilities database
A medium severity vulnerability (CVE-2021-30558) was identified in Google Chrome's content security policy implementation. The vulnerability was discovered by Jun Kokatsu from Microsoft Browser Vulnerability Research on December 19, 2018, and was fixed in Chrome version 91.0.4472.77 released on May 25, 2021. The issue affects all versions of Google Chrome prior to 91.0.4472.77 (Chrome Release).
The vulnerability is characterized as an insufficient policy enforcement in content security policy that could allow a remote attacker to bypass content security policy via a crafted HTML page. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD).
If exploited, this vulnerability could allow attackers to bypass the content security policy protections, potentially leading to high impacts on confidentiality, integrity, and availability of the affected system. The CVSS score of 8.8 indicates significant potential impact if successfully exploited (NVD).
The vulnerability requires user interaction and can be exploited remotely by an attacker with no privileges required. The attack complexity is considered low, making it relatively straightforward to exploit if proper conditions are met (NVD).
The vulnerability has been patched in Chrome version 91.0.4472.77. Users are advised to update their Chrome browsers to this version or later to mitigate the risk. The fix was included as part of Chrome's stable channel update for desktop platforms (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."