CVE-2023-36029

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Nov 3, 2023
Updated: Jan 1, 2025

Summary

CVE-2023-36029 is a new spoofing vulnerability affecting Microsoft Edge browsers based on Chromium. This issue allows malicious actors to manipulate the display of web pages, potentially deceiving users into believing they are interacting with a trustworthy site. The vulnerability arises from an inadequately validated user interface element, which can be exploited through specially crafted web content. The exploitation of this flaw may lead to social engineering attacks, potentially resulting in sensitive information disclosure or unauthorized system access. Users are advised to keep their browsers updated to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share