Microsoft Edge vulnerable to cookie and password theft

Costea Lestoc By: Costea Lestoc
2 minute read

Home » News » Microsoft Edge vulnerable to cookie and password theft

The Microsoft Edge browser seems to have a severe password vulnerability. Recent reports reveal that attackers or hackers could easily obtain user password and cookie files for online accounts, a vulnerability that was discovered by security expert Manuel Caballero, someone with vast experience of unearthing Edge and Internet Explorer bugs and flaws.

Attackers can bypass Edge’s SOP protection

The vulnerability lets an attacker load and execute malicious code using data URIs, Meta refresh tag, and domainless pages such as about:blank. This exploitation technique has many variations and Caballero showed the ways in which a hacker could execute code on high-profile sites just by tricking users to access a malicious URL.

Caballero showed three demos in which he executed code on the Bing homepage, tweeted in the name of another user, and stole the password and cookie files from a Twitter account.

The last attack re-exposed a security error in the design of modern browsers: the hacker’s ability to logout a user, load a login page, and steal the user’s credentials automatically filled in by the browser’s password autofill feature.

The vulnerability is still unpatched. For this reason, Caballero provided demos to download so users can inspect the source code and make sure their passwords and cookies aren’t uploaded anywhere.

Attacks are automated by malvertising

It also seems that attacks can be customized to dump the passwords or cookies of more online services such as Amazon, Facebook, and more. Only Edge is affected because “UXSS/SOP bypasses tend to be particular to each browser.”

Modern ads deliver JavaScript code to browsers and this is why attackers can facilitate malvertising campaigns to automate the delivery of this exploit to a huge amount of victims.

For more information, you can read Caballero’s technical description of the issue.

RELATED STORIES TO CHECK OUT:

Discussions

Next up

How to delete Steam Cloud saves [STEP-BY-STEP GUIDE]

Vlad Turiceanu avatar. By: Vlad Turiceanu
2 minute read

From the old days of hundreds of CDs and DVDs, larger and larger hard drives, to cloud services now, gaming has grown significantly. The need […]

Continue Reading

Windows Sandbox error 0x80070002 after update [QUICK FIX]

Alexandru Voiculescu By: Alexandru Voiculescu
2 minute read

Many Reddit users encountered error 0x80070002 on Windows Sandbox following the Windows 10 v1903 update. One user reported the following situation: Windows Sandbox giving 0x80070002 […]

Continue Reading

Action Center still broken on Tablet Mode in Windows 10 v1903

Alexandru Voiculescu By: Alexandru Voiculescu
Less than a 1 minute read

Many users reported several Action center issues in Tablet Mode after installing Windows 10 v1903. One user asked if the known issues persisted after the […]

Continue Reading