Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions
ID: 0013b482-2e45-5580-81ff-e62f53f80beb
STIX ID: report--0013b482-2e45-5580-81ff-e62f53f80beb
Feed Name: The Hacker News
Guardio Labs disclosed CVE-2024-21388, a privilege-escalation bug in Chromium-based Microsoft Edge that abused a private marketing API (edgeMarketingPagePrivate) accessible from allowlisted Microsoft domains to stealthily install arbitrary extensions from the Edge Add-ons store without user consent. Microsoft patched the issue in Edge 121.0.2277.83 on January 25, 2024; exploitation requires attacker-controlled JavaScript on an allowlisted site and could enable extension-based persistence and potential sandbox escape, but Guardio reported no evidence of active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
