Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:android:*:*
A vulnerability in Microsoft Edge for Android allows unauthorized attackers to access private personal information over the network. This issue arises from the browser's handling of sensitive data, which can be intercepted by malicious actors.
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information from the user's browser, associated with the vulnerable URL.
To reproduce this vulnerability, a user must visit an attacker-controlled webpage and perform two tap gestures to activate the autofill feature. This interaction will trigger the browser to disclose sensitive information to the attacker.
Users can download the security update for this vulnerability through the Microsoft Edge Security Update Guide.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.