CVE-2023-21794

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 14, 2023
Updated: Jan 1, 2025
CWE ID 290

Summary

CVE-2023-21794 is a new spoofing vulnerability affecting Microsoft Edge, which is based on Chromium. Hackers can potentially manipulate the display of webpage content, creating a phishing-like attack where users believe they are interacting with a trusted site. This issue can lead to user information being disclosed or stolen, making it a significant security risk. Microsoft has released a patch to address this vulnerability, and users are encouraged to update their browsers as soon as possible to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Edge Chromium

Affected Vendors

  • Microsoft