CVE-2023-36880
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Dec 7, 2023
Updated: Jan 1, 2025
Summary
CVE-2023-36880 is an information disclosure vulnerability affecting Microsoft Edge, the Chromium-based web browser. Maliciously crafted web content can cause the browser to unintentionally reveal sensitive information, potentially including browser history or cookies. An attacker could exploit this vulnerability to gain insight into a user's browsing activities, posing a privacy risk. Microsoft is working on a patch to address this issue and users are encouraged to keep their browsers up-to-date to protect against potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Microsoft Edge Chromium
Affected Vendors
- Microsoft