CVE-2018-8235 is a security feature bypass vulnerability in Microsoft Edge that allows improper handling of cross-origin requests. This flaw, dubbed "Wavethrough," can lead to sensitive data leakage and affects Microsoft Edge on Windows 10 and Windows Server 2016. With a CVSS score of 4.3 (Medium), it requires user interaction and network access, potentially resulting in low confidentiality impact. While there is no known public exploit code or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential. It is not currently on CISA's KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.