#VU14755 Information disclosure in Microsoft Edge - CVE-2018-8366
Published: September 11, 2018 / Updated: September 12, 2018
Microsoft Edge
Microsoft
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type. A remote attacker can create a specially crafted web page, bypass the cross-origin policy and view URL of a cross-origin request.