CVE-2024-26246
published 2024-03-14CVE-2024-26246: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
PriorityP412low3.9CVSS 3.1
AVPACLPRHUINSUCHINAN
EPSS
0.65%
46.9th percentile
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge | < 122.0.2365.92 | 122.0.2365.92 |
| microsoft | microsoft_edge_for_android | >= 1.0.0 < 122.0.2365.92 | 122.0.2365.92 |
| msrc | microsoft_edge_for_android | — | — |
CVSS provenance
nvdv3.13.9LOWCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_msrc3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pxv9-wjf4-mr7m: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-03-15
CVE-2024-26246 [LOW] CWE-1220 GHSA-pxv9-wjf4-mr7m: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
vendor_msrc·2024-03-12·CVSS 3.9
CVE-2024-26246 [LOW] CWE-1220 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this could bypass the Edge AutoFill Protection feature
FAQ: According to the CVSS metric, the attack vector is physical (AV:P), user interaction is required (UI:R), and privileges required is high (PR:H). What does that mean for this vulnerability?
An authorized attacker with physical access to a victim's unsecured Android phone must use the autofill feature on Edge Android to access victim's saved credentials.
FAQ:
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
122.0.2365.92
3/14/2024
122.0.6261.128/.129
Extended Stable
122.0.236
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-03-14
Published