CVE-2024-26246: low-severity vulnerability in Microsoft Edge for Android
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.9epss 0.6%
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
In short
A security feature in Microsoft Edge can be bypassed, potentially allowing attackers to circumvent protections designed to keep you safe. This is a relatively minor issue that requires specific conditions to exploit.
Technical detail
A security feature bypass vulnerability in Chromium-based Microsoft Edge allows circumvention of intended protections through CWE-1220 (Improper Restriction of Rendered UI Layers or Frames). The vulnerability requires user interaction and specific attack conditions, resulting in low practical impact (CVSS 3.9).
Summary generated and translated by AI from the official description.
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Microsoft Edge for AndroidRelated CVEs — Microsoft Edge for Android
In the same product, most dangerous first.
CVE-2021-24100MEDIUMMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 3.1%CVE-2021-26439MEDIUMMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 2.9%CVE-2020-17153MEDIUMMicrosoft Edge for Android Spoofing VulnerabilityEPSS 2.5%CVE-2022-23258MEDIUMMicrosoft Edge for Android Spoofing VulnerabilityEPSS 1.6%CVE-2025-21253MEDIUMMicrosoft Edge for IOS and Android Spoofing VulnerabilityEPSS 1.2%CVE-2024-26196MEDIUMMicrosoft Edge for Android (Chromium-based) Information Disclosure VulnerabilityEPSS 1.2%