Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A vulnerability in Microsoft Edge (Chromium-based) allows unauthorized attackers to disclose sensitive information over the network. This issue arises from operations on a resource after its expiration or release.
Exploitation of this vulnerability could lead to unauthorized information disclosure.
To exploit this vulnerability, an attacker would need to host a specially crafted website designed to activate the autofill feature in Microsoft Edge. The attacker must then convince a user to visit the website and perform two tap gestures to trigger the vulnerability. This could be done through an email or instant message enticement, or by sending an attachment that the user opens.
Users can download the security update for Microsoft Edge (Chromium-based) from the Microsoft Edge Release Notes - Security page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.