CVE-2021-42308: Microsoft Edge (Chromium-based) Spoofing Vulnerability

Overview

Severity
Low (CVSS 3.1)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
Category
Edge - Chromium
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Nov
Released
2021-11-19
Last Updated
2021-12-07
EPSS Score
1.72% (percentile: 82.4%)

FAQ

What is the version information for this release? Microsoft Edge Version Date Released Based on Chromium Version 96.0.1954.29 11/19/2021 96.0.4664.45

Affected Products (1)

Browser

  • Microsoft Edge (Chromium-based)

Acknowledgments

<a href="https://twitter.com/Kirtikumar_A_R">Kirtikumar Anandrao Ramchandani</a>

Revision History

  • 2021-11-19: Information published.
  • 2021-11-22: Added an FAQ. This is an information change only.
  • 2021-11-30: Added an acknowledgement. This is an informational change only.
  • 2021-12-07: Updated severity of Microsoft Edge (Chromium-based) from important to low. This is an informational change only.