CVE-2016-0125: Microsoft Edge
Low severity, CVSS 3.1. EPSS: 11.9% chance of exploitation in the next 30 days.
Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web site, aka "Microsoft Edge Information Disclosure Vulnerability."
Affected products
- Microsoft Edge: any version
Published 2016-03-09. Last modified 2026-06-17.