CVE-2024-26196
published 2024-03-21CVE-2024-26196: Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
PriorityP417medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
1.24%
65.9th percentile
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge | < 122.0.2365.63 | 122.0.2365.63 |
| microsoft | microsoft_edge_for_android | >= 1.0.0 < 122.0.2365.63 | 122.0.2365.63 |
| msrc | microsoft_edge_for_android | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
vendor_msrc·2024-02-13·CVSS 4.3
CVE-2024-26196 [MEDIUM] CWE-259 Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L) but have no effect on integrity (I:N) or on availability (A:N). What does that mean for this vulnerability?
An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality) but not all resources within the impacted component may be divulged to the attacker. The attacker cannot make changes to disclosed information (Integrity) or limit access to the resource (Availability).
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially cr
GHSA
GHSA-gwrw-fm59-98g3: Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
ghsa_unreviewed·2024-03-21
CVE-2024-26196 [MEDIUM] CWE-259 GHSA-gwrw-fm59-98g3: Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-03-21
Published