Vulnerability record · CVE-2016-0161 · published 12 April 2016
CVE-2016-0161: Microsoft Edge Same Origin Policy bypass
Microsoft · Edge
Microsoft Edge contains a Same Origin Policy bypass reachable by remote attackers through unspecified vectors. The flaw is an elevation of privilege issue distinct from CVE-2016-0158. A Same Origin Policy bypass matters because it undermines the browser's core isolation boundary between sites.
Description
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0158.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Automated analysis
high priorityThe flaw breaks a fundamental browser security boundary and carries a very high EPSS score, though exploitation requires user interaction and no confirmed in-the-wild use is recorded.
What it is
Microsoft Edge contains a Same Origin Policy bypass reachable by remote attackers through unspecified vectors. The flaw is an elevation of privilege issue distinct from CVE-2016-0158. A Same Origin Policy bypass matters because it undermines the browser's core isolation boundary between sites.
Impact
An attacker can bypass the Same Origin Policy, gaining the ability to read or manipulate content across origins that should be isolated. The CVSS vector rates integrity impact as High with no confidentiality or availability impact.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R), meaning a victim must be induced to load attacker-controlled content in Edge. No further detail on the specific vectors is provided in the record.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag; EPSS is 0.6877 (99.3rd percentile), indicating high predicted likelihood of exploitation activity despite the absence of confirmed in-the-wild data.
What to do
- Apply the Microsoft security update MS16-038 for Edge, which addresses this vulnerability.
- Keep Edge and the underlying Windows platform current with all subsequent cumulative updates.
- Restrict or monitor browsing to untrusted sites and enforce SmartScreen and other Edge security features.
- Where feasible, isolate browsing activity to reduce the impact of a cross-origin bypass.
Detection
- Monitor for Edge crashes or anomalous renderer behavior around the patch timeframe.
- Hunt for suspicious cross-origin script or iframe activity in browser or proxy logs.
- Review endpoint telemetry for unusual child processes or script execution originating from Edge.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0161 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0161), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.