Description
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published: 2025-12-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Spoofing
Action: Assess Impact
AI Analysis

Impact

The vulnerability allows an attacker to deceive users by presenting counterfeit content or identities within Microsoft Edge (Chromium-based) on Android devices. This can lead to users believing they are interacting with a legitimate site or source when they are not, potentially facilitating phishing or social engineering attacks. The weakness is classified under CWE-290 (Authentication Spoofing) and CWE-451 (Code Review Does Not Verify Critical Function). The design of the browser means that the spoofed content could appear seamless to the user, undermining trust and increasing the risk of credential disclosure if the user proceeds to enter personal information.

Affected Systems

Affected systems are Microsoft Edge for Android, a Chromium‑based browser distributed by Microsoft. No specific version range is listed in the CNA data, so all releases of the Android Edge browser at the time of disclosure are potentially impacted.

Risk and Exploitability

The CVSS base score of 3.1 indicates a low overall impact. The EPSS score of less than 1% suggests a very low probability that this weakness is being actively exploited in the wild, and it is not currently listed in the CISA KEV catalog. The likely attack vector is inferred to be through malicious or compromised web content rendered in the Edge Android browser, where the spoofed assets would be viewed by unsuspecting users. Because the flaw does not grant code execution or privilege escalation, the threat is confined to the user's trust and visibility within the web page rendered by the browser.

Generated by OpenCVE AI on April 20, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure Microsoft Edge for Android is updated to the latest version, which contains the vendor’s patch for this spoofing flaw.
  • Enable Microsoft’s “SmartScreen” or equivalent phishing protection in Edge settings to reduce the likelihood of user interaction with spoofed content.
  • If Edge is not required on the device, uninstall or disable the browser and use Microsoft’s recommended alternative Android browsers that receive timely security updates.

Generated by OpenCVE AI on April 20, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Feb 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451

Tue, 06 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft edge Chromium
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:android:*:*
Vendors & Products Microsoft edge Chromium

Fri, 19 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Description Microsoft Edge (Chromium-based) Spoofing Vulnerability
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge
CPEs cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
Vendors & Products Microsoft
Microsoft edge
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-04-16T14:19:07.967Z

Reserved: 2025-11-13T16:18:07.468Z

Link: CVE-2025-65046

cve-icon Vulnrichment

Updated: 2025-12-19T15:17:11.186Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T22:16:01.750

Modified: 2026-02-20T17:25:50.093

Link: CVE-2025-65046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T15:45:10Z

Weaknesses