CVE-2023-36727

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Sep 15, 2023
Updated: Jan 1, 2025

Summary

CVE-2023-36727 refers to a spoofing vulnerability identified in Microsoft Edge, the Chromium-based web browser. Hackers can manipulate the browser's address bar to display fraudulent URLs, potentially deceiving users into entering sensitive information or downloading malware. This security flaw poses a significant risk to users who trust the legitimacy of the URL displayed in their browser. Microsoft is actively working on a patch to mitigate this issue. Until then, users are advised to exercise caution when entering personal information online, verify URLs before interacting with them, and keep their browser and operating system up-to-date.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Edge Chromium

Affected Vendors

  • Microsoft