CVE-2024-26163
published 2024-03-14CVE-2024-26163: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
PriorityP424medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
EPSS
2.09%
79.7th percentile
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 122.0.2365.92 | 122.0.2365.92 |
| microsoft | microsoft_edge | >= 1.0.0 < 122.0.2365.92 | 122.0.2365.92 |
| microsoft | microsoft_edge_extended_stable | >= 1.0.0 < 122.0.2365.92 | 122.0.2365.92 |
| msrc | microsoft_edge | — | — |
| msrc | microsoft_edge_extended_stable | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcf9-x527-mw6v: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-03-15
CVE-2024-26163 [MEDIUM] CWE-693 GHSA-qcf9-x527-mw6v: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
vendor_msrc·2024-03-12·CVSS 4.7
CVE-2024-26163 [MEDIUM] CWE-693 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
FAQ: How could an attacker exploit this vulnerability via the Network?
An attacker could host a specially crafted website designed to exploit the vulnerability through Microsoft Edge and then convince a user to view the website. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action, typically by an enticement in an email or instant message, or by getting the user to open an attachment sent through email.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to a browser sandbox escape.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-03-14
Published