Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A vulnerability in Microsoft Edge (Chromium-based) allows unauthorized attackers to disclose sensitive information over a network. This issue arises from improper link resolution before file access, commonly known as 'link following'.
Exploitation of this vulnerability could lead to unauthorized information disclosure.
To exploit this vulnerability, an attacker could host a specially crafted website designed to take advantage of the improper link resolution. The attacker would then need to convince a user to visit the website, such as through an email or instant message. Once the user is on the site, the vulnerability could be triggered by performing two tap gestures that activate the autofill feature.
Users can download the security update for Microsoft Edge (Chromium-based) from the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.