Two zero-day vulnerabilities in the updated versions of Microsoft Edge and Internet Explorer could enable outsiders to access confidential information shared between websites, according to new security research highlighted by Trend Micro Tuesday. The browser vulnerabilities were first made public March 29 by James Lee, a 20-year-old security researcher who says he first notified Microsoft about the issues 10 months ago. A Trend Micro analysis of the attacks found that if a web user visits a malicious page using either browser, attackers can exploit a process known as Origin Validation Error to gather information about other pages the user visited. Thieves could use this technique to bypass security measures and steal financial or other personal information, researchers said. “The browser is not restricting information about the website redirection properly, and instead allows [hackers] to access information about the client’s activities on other websites,” Trend Micro said in a blog post. “In […]
The post Microsoft Edge, Internet Explorer zero-days could allow spying on your browsing activity appeared first on CyberScoop.
Continue reading Microsoft Edge, Internet Explorer zero-days could allow spying on your browsing activity→