CVE-2024-26247
published 2024-03-22CVE-2024-26247: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
PriorityP421medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
EPSS
1.12%
62.8th percentile
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge | < 123.0.2420.53 | 123.0.2420.53 |
| microsoft | microsoft_edge | >= 1.0.0 < 123.0.2420.53 | 123.0.2420.53 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
vendor_msrc·2024-03-12·CVSS 4.7
CVE-2024-26247 [MEDIUM] CWE-269 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
FAQ:
Microsoft Edge Channel
Microsoft Edge Version
Date Released
Based on Chromium Version
Stable
123.0.2420.53
3/22/2024
123.0.6312.58/.59
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be
GHSA
GHSA-qq9q-r5w2-268r: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-03-23
CVE-2024-26247 [MEDIUM] CWE-269 GHSA-qq9q-r5w2-268r: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-03-22
Published