Security restrictions bypass in Microsoft Edge - CVE-2018-8463
Published: September 11, 2018 / Updated: September 12, 2018
Microsoft Edge
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to visit a specially crafted web page, bypass AppContainer sandbox and execute arbitrary JavaScript code with elevated privileges.