Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:android:*:*
A vulnerability allowing unauthorized access control bypass has been identified in Microsoft Edge for Android, specifically in version 150.0.4078.48. This flaw enables an attacker to circumvent a security feature over the network, potentially leading to unauthorized access or actions.
Exploitation of this vulnerability allows for a security feature bypass, enabling unauthorized users to bypass expected access controls.
To reproduce this vulnerability, an unauthorized attacker must control a webpage that the user visits. The user must then perform two tap gestures to activate the autofill feature, thereby exploiting the access control bypass.
Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48. For more details, refer to the Microsoft Edge Release Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.