← back
CVE-2024-26246lowCWE-1220

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.9epss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
In short

A security feature in Microsoft Edge can be bypassed, potentially allowing attackers to circumvent protections designed to keep you safe. This is a relatively minor issue that requires specific conditions to exploit.

Technical detail

A security feature bypass vulnerability in Chromium-based Microsoft Edge allows circumvention of intended protections through CWE-1220 (Improper Restriction of Rendered UI Layers or Frames). The vulnerability requires user interaction and specific attack conditions, resulting in low practical impact (CVSS 3.9).

Summary generated and translated by AI from the official description.
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C