#VU98826 Multiple Interpretations of UI Input in Microsoft Edge - CVE-2024-43577
Published: October 21, 2024
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to an error when handling extension's popups. A remote attacker can trick the victim into visiting a specially crafted webpage, show an extension's popup over a permission prompt or screen share dialog, which allows the extension to spoof parts of the prompt's UI that show origin.