CVE-2023-36880

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Dec 7, 2023
Updated: Jan 1, 2025

Summary

CVE-2023-36880 is an information disclosure vulnerability affecting Microsoft Edge, the Chromium-based web browser. Maliciously crafted web content can cause the browser to unintentionally reveal sensitive information, potentially including browser history or cookies. An attacker could exploit this vulnerability to gain insight into a user's browsing activities, posing a privacy risk. Microsoft is working on a patch to address this issue and users are encouraged to keep their browsers up-to-date to protect against potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Edge Chromium

Affected Vendors

  • Microsoft