Jump to content

Microsoft shrugs off report that Edge can expose user identities from JS Fetch requests


Recommended Posts

Posted

Updated An independent researcher claims to have uncovered a security flaw in Microsoft Edge.

The issue enables any website to identify someone by their username from another website, according to Ariel Zelivansky. More specifically the bod alleges that Edge exposes the URL of any JavaScript Fetch response, in contradiction to the specification. This is a problem because it's possible to identify netizens by crafting a fetch() request in a webpage that will redirect to a URL containing the visitor's username (e.g. requesting https://facebook.com/me will pull in https://facebook.com/username).

ย 

Updated to add

Despite Microsoft's silence, it turns out the Windows giant has decided to assign an engineer to look into the matter โ€“ but it is still not being treated as a security vulnerability.

ย 

http://www.theregister.co.uk/2017/04/20/ms_edge_vuln_dispute/

ย 

ย  ย  ย  ย  ย ย 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.



ร—
ร—
  • Create New...