CVE-2024-30058
published 2024-06-13CVE-2024-30058: Microsoft Edge (Chromium-based) Spoofing Vulnerability
PriorityP423medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.39%
31.8th percentile
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 126.0.2592.56 | 126.0.2592.56 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 126.0.2592.56 | 126.0.2592.56 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Edge up to 124.0.2478.109 insufficient warning (EUVD-2024-27995)
vuldb·2026-07-21·CVSS 5.4
CVE-2024-30058 [MEDIUM] Microsoft Edge up to 124.0.2478.109 insufficient warning (EUVD-2024-27995)
A vulnerability marked as critical has been reported in Microsoft Edge. The affected element is an unknown function. Performing a manipulation results in insufficient ui warning of dangerous operations.
This vulnerability is identified as CVE-2024-30058. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-j67r-3cm4-272w: Microsoft Edge (Chromium-based) Spoofing Vulnerability
ghsa_unreviewed·2024-06-13
CVE-2024-30058 [MEDIUM] CWE-290 GHSA-j67r-3cm4-272w: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft
Microsoft Edge (Chromium-based) Spoofing Vulnerability
vendor_msrc·2024-06-11·CVSS 5.4
CVE-2024-30058 [MEDIUM] CWE-357 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability?
Limited information from the victim's browser associated with the vulnerable URL can be sent to the attacker by the malicious code.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the permissions dialog feature prompt presented to users when initiating a download.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attack
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-13
Published