Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A use-after-free vulnerability has been identified in Microsoft Edge (Chromium-based) versions through 150.0.4078.48. This vulnerability allows an unauthorized attacker to execute code remotely over the network. Exploitation requires user interaction, such as opening a specially crafted file or visiting an attacker-controlled website.
Exploitation of this vulnerability could lead to remote code execution on the affected system.
To reproduce this vulnerability, a user must open a specially crafted file from an attacker, which can initiate remote code execution. Alternatively, an attacker could host a website designed to exploit this vulnerability. The user would need to visit the site and perform two tap gestures to activate autofill, thereby triggering the exploit.
Users can download the security update for Microsoft Edge (Chromium-based) from the Microsoft Edge Release Notes - Security page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.