Incorrect default permissions in Microsoft Edge - CVE-2024-38222
Published: September 12, 2024
Microsoft Edge
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error in Edge WebUI permission implementation. A remote attacker can trick a victim into visiting a specially crafted website and gain access to sensitive information by manipulating granted permissions, such as access to camera and microphone.