CVE-2023-21794LowCVSS 4.3
Microsoft Edge (Chromium-based) Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? The user would need to access the URL of the malicious website, which could spoof the content of a legitimate website, and then click a popup displayed on that site.
What is the version information for this release? Microsoft Edge Version Date Released Based on Chromium Version 110.0.1587.41 2/9/2023 110.0.5481.78
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.
🎯 Affected products1
- Microsoft Edge (Chromium-based)
✅ Remediation
KBRelease Notes (Security Update) — fixed build 110.0.1587.41