The 20-year-old security researcher James Lee publicly disclosed details and proof-of-concept exploits for two zero-day vulnerabilities in Microsoft web browsers. One of the flaws affects the latest version of the Edge Browser, both flaws could be exploited by a remote attacker to bypass same-origin policy on the victims web browser. The attacker just needs to trick victims into visiting a malicious website created to steal their sensitive data (i.e. login session, cookies), from other sites visited on the same browser.”]
Source: https://securityaffairs.co/wordpress/83080/hacking/microsoft-browser-zero-day.html

