Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A type confusion vulnerability has been identified in Microsoft Edge (Chromium-based), specifically in version 150.0.4078.48. This vulnerability allows an unauthorized attacker to perform spoofing over a network. The issue arises from the access of resources using incompatible types, which could be exploited to deceive users or systems.
Exploitation of this vulnerability could lead to spoofing attacks, where an attacker could create deceptive or invisible form elements that a user might inadvertently interact with.
To reproduce this vulnerability, an attacker would need to host a specially crafted website designed to exploit the type confusion issue in Microsoft Edge. The attacker would then have to convince a user to visit the website, such as through an email or message enticement.
Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48. For more details, refer to the Microsoft Edge Release Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.