CVE-2020-17153MediumCVSS 4.3

Microsoft Edge for Android Spoofing Vulnerability

Published
December 8, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit the vulnerability? An attacker would have to convince a user to visit a malicious website, typically via an enticement in email or instant message, or by getting them to open an email attachment. What is the attack vector for this vulnerability? The attack vector is address bar spoofing. A malicious website could spoof the contents of a URL bar via a specially crafted HTML page's long URL and then use it for a phishing attack.

🎯 Affected products1

  • Microsoft Edge for Android

🔗 References (1)