Security News Scammers Can Use Microsoft Edge Security Feature to Display Fake Warnings

BoraMurdar

Super Moderator
Thread author
Verified
Staff Member
Well-known
Aug 30, 2012
6,598
Manuel Caballero explains in a blog post that Microsoft Edge has a vulnerability that allows ms-appx: and ms-appx-web: commands to generate fake alerts very similar to the one issued by SmartScreen and which could be used in more complex schemes.

For example, the attackers can use these warnings to convince unsuspecting victims to call a phone number, where phone scammers would attempt to steal users’ information.

“As a bonus, when we place a telephone-like number, a link is automatically created so the user can call us with a single click. Very convenient for these scammers,” the researcher notes.

Microsoft’s SmartScreen
SmartScreen is a feature that’s available in both Microsoft Edge and Internet Explorer, but this bug has been demonstrated only in the default Windows 10 browser.

In essence, SmartScreen is a super helpful feature that keeps users protected from websites that could be used to spread malware.

“SmartScreen checks the sites you visit against a dynamic list of reported phishing sites and malicious software sites. If it finds a match, SmartScreen will show you a warning letting you know that the site has been blocked for your safety,” Microsoft explains.

Microsoft is working hard to improve browser security in Edge, so it goes without saying that this is going to be fixed for sure in the coming updates.

Edge receives updates on a regular basis and large OS updates, such as the upcoming Creators Update, bring a plethora of improvements for the browser, including features and fixes that are specifically supposed to make the app faster, more reliable and secure.
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,513
I don't use my Edge browser, but Wife does.

I decided to take a snapshot with RollBack, probably run Drive Cloner later today if I can. I don't worry about myself, but my Wife is the worst for clicking messages.

I use my Edge browser, and my Wife does.:)
She was not especially happy at first, but now it is OK.;)

It should not be a problem here as i am a long way from using Edge as a browser. :)
You are six (astronomical) light years away!
One year for each firefox addon.:)
There were good times, when I used many firefox addons.o_O

I am using Edge, but sometimes it looks like a child.
 
Last edited by a moderator:

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,513
Maybe a good reason to disable Smartscreen and rely on your other security,if you have any.
I really never use the Edge Browser.

I like reading about security vulnerabilities, it is interesting. Yet, in this case the danger is only theoretical, because Edge is very unpopular, and no one is going to exploit it. The event probability is like drowning in the desert.:)
I will not be so sure that 'other security' has considerably less vulnerabilities than Edge.:(
Choosing or not choosing Edge, that is not the question. Both choices are good (if we skip addons).
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top