在 Microsoft Edge for iOS 中,由于用于 LLM(大语言模型)提示词构建的输入未经充分净化,允许未授权攻击者通过网络执行欺骗(spoofing)攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft Edge (Chromium-based) | 1.0.0.0< 150.0.4078.50 |
affected |
| Microsoft | Microsoft Edge for iOS | 1.0.0.0< 150.0.4078.50 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft Edge (Chromium-based) | 1.0.0.0 ~ 150.0.4078.50 | - |
|
| Microsoft | Microsoft Edge for iOS | 1.0.0.0 ~ 150.0.4078.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72984 | 8.8 HIGH | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-66324 | 6.5 MEDIUM | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-70309 | 5.4 MEDIUM | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2026-66323 | 5.4 MEDIUM | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-62904 | 5.4 MEDIUM | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-58616 | 4.4 MEDIUM | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability |
| CVE-2026-66798 | 4.3 MEDIUM | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
No comments yet