#VU22671 Permissions, Privileges, and Access Controls in Microsoft Edge - CVE-2019-1413
Published: November 12, 2019
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to an error when handling extension requests that doe not request host permission for all_urls. A remote attacker can create a specially crafted website, trick the victim into visiting it and bypass built-in security features.