SB2024031506 - Security restrictions bypass in Microsoft Edge for Android
Published: March 15, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2024-26246)
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to an error in autofill feature on Edge Android. An attacker with physical access to an Android device can bypass the Edge AutoFill Protection feature and access victim's saved credentials.
Remediation
Install update from vendor's website.