Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A type confusion vulnerability has been identified in Microsoft Edge (Chromium-based), allowing unauthorized attackers to execute code remotely. This issue arises from accessing a resource using an incompatible type, which could be exploited over the network.
Exploitation of this vulnerability could lead to unauthorized remote code execution.
To reproduce this vulnerability, a user must be convinced to open a specially crafted file or visit a website that exploits the type confusion. This requires two sequential taps to activate autofill, taking advantage of the vulnerability.
Users can download the security update for Microsoft Edge (Chromium-based) from the Microsoft Edge Release Notes Security page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.