CVE-2024-26192
published 2024-02-23CVE-2024-26192: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
PriorityP338high8.2CVSS 3.1
AVNACLPRNUIRSCCHINAL
EPSS
1.52%
72.0th percentile
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 122.0.2365.52 | 122.0.2365.52 |
| microsoft | microsoft_edge | >= 1.0.0 < 122.0.2365.52 | 122.0.2365.52 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:L
vendor_msrc8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
vendor_msrc·2024-02-13·CVSS 8.2
CVE-2024-26192 [HIGH] CWE-359 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
FAQ:
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
122.0.2365.52
2/23/2024
122.0.6261.57/.58
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to a browser sandbox escape.
FAQ: How could an attacker exploit this vulnerability via the Network?
An attacker could host a specially crafted website designed to exploit the vulnerability through Microsoft Edge and then convince a user to view the website. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a
GHSA
GHSA-3rcm-9xw5-hpx9: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
ghsa_unreviewed·2024-02-24
CVE-2024-26192 [HIGH] CWE-359 GHSA-3rcm-9xw5-hpx9: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-23
Published