CVE-2018-8370 is an information disclosure vulnerability in Microsoft Edge, affecting Windows 10 and Windows Server 2016, where the WebAudio Library improperly handles audio requests. This vulnerability has a low CVSS score of 3.1, indicating a network-based attack requiring high attack complexity and user interaction, with a potential impact of limited confidentiality loss. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Despite minimal community discussion and media coverage, Microsoft addressed this flaw in their August 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.