Microsoft Edge Browser Vulnerabilities

Risk:
high
Damage:
high
Platform(s):
Microsoft
Advisory ID:
ngCERT-2020-0041
Version:
N/A
CVE:
CVE-2021-34506
Published:
July 1, 2021

Summary


A Microsoft Edge vulnerability that could allow hackers steal secrets from any website was discovered and thereby prompting Microsoft to release updates for the Edge browser, including a fix. This bypass vulnerability could allow a remote attacker to bypass implemented security restrictions to inject and execute arbitrary code on any website just by sending a message.

Description & Consequence


The vulnerability, tracked as CVE-2021-34506, stems from universal cross-site scripting, or UXSS, which triggers when a webpage is automatically translated using Microsoft Edge browser's built-in feature via Microsoft translator. Microsoft Translator is a feature through which the browser automatically prompts users to translate a webpage when the page is in a language other than those listed under the user’s preferred languages in settings. It was found that the translation feature contained a piece of vulnerable code that failed to sanitize input which could allow threat actors to insert malicious JavaScript code anywhere in the webpage and subsequently executed when the user clicks the prompt on the address bar to translate the page.

When such vulnerabilities are found and exploited, the behavior of the browser is affected and its security features may be bypassed or disabled, allowing an attacker to perform arbitrary code execution and privilege escalation on any website to steal sensitive data.

Solution


Stakeholders are recommended to install the latest version of Microsoft Edge (version 91.0.864.59) which can be downloaded by accessing Settings and more > About Microsoft Edge (edge://settings/help).

Reference


  1. https://thehackernews.com/2021/06/microsoft-edge-bug-couldve-let-hackers.html.
  2. https://heimdalsecurity.com/blog/microsoft-edge-vulnerability-couldve-allowed-hackers-to-steal-files/
  3. https://threatpost.com/microsoft-edge-browser-uxss-attacks/167389/

Revision


Related Articles