• Microsoft Edge has three unpatched “Same Origin Policy” security holes

    Catalin Cimpanu at BleepingComputer reports:

    Argentinean security researcher Manuel Caballero has discovered another vulnerability in Microsoft’s Edge browser that can be exploited to bypass a security protection feature and steal data such as passwords from other sites, or cookie files that contain sensitive information.

    The vulnerability is a bypass of Edge’s Same Origin Policy (SOP), a security feature that prevents a website from loading resources and code from other domains except its own.

    Edge still has a long way to go.

    Thx, @VessOnSecurity