← back
CVE-2024-26167mediumCWE-1021

Microsoft Edge for Android Spoofing Vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft Edge for Android has a spoofing vulnerability that allows an attacker to deceive users into thinking they're visiting a legitimate website when they're actually on a malicious one. This matters because users might unknowingly share sensitive information or download harmful content.

Technical detail

The vulnerability (CWE-1021: Improper Restriction of Rendered UI Layers) enables attackers to spoof the user interface of Microsoft Edge on Android, potentially masking the true origin or destination of user actions. This could involve overlaying or manipulating visual elements to deceive users about which website they are interacting with, requiring only that the user interact with the spoofed interface.

Summary generated and translated by AI from the official description.
Microsoft Edge for Android Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C