CVE-2021-31982
published 2023-07-01CVE-2021-31982: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.31%
67.6th percentile
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 91.0.864.37 | 91.0.864.37 |
| microsoft | microsoft_edge | >= 1.0.0 < 91.0.864.37 | 91.0.864.37 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3ww-6w46-7xwj: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
ghsa_unreviewed·2023-07-01
CVE-2021-31982 [HIGH] CWE-693 GHSA-r3ww-6w46-7xwj: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
vendor_msrc·2021-05-11·CVSS 8.8
CVE-2021-31982 [HIGH] Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user have multiple browser instances open of the affected version of Microsoft Edge (Chromium-based), one of which is a specially crafted website hosted by the attacker. The user would need to access the URL of the malicious website and then click a popup displayed on that site.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), integrity (I:H), and (A:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability could lead to a full compromise of the browser
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-01
Published