Description
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Published: 2026-03-13
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofing / Authentication Bypass
Action: Apply Update
AI Analysis

Impact

Microsoft Edge (Chromium-based) for Android is affected by a spoofing vulnerability that allows a malicious site to masquerade as a trusted resource. The assignment of CWE‑290 (Improper Authentication) and CWE‑451 (Blind Race Condition) suggests the flaw involves an authentication weakness potentially combined with a concurrency issue, which could be used to spoof the identity of a legitimate site or resource. Based on this, an attacker might be able to trick a user into interacting with a site that appears to be authentic, undermining the integrity of the browsing session. The vulnerability does not expose arbitrary code execution, denial of service, or other more severe impacts beyond spoofing.

Affected Systems

The affected product is Microsoft Edge for Android, distributed by Microsoft. No specific version is identified in the advisory; therefore, all current releases of the Android application should be considered potentially vulnerable until an official patch is released.

Risk and Exploitability

The CVSS score of 5 indicates a moderate risk level, while the EPSS score of less than 1 % reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. It is inferred that exploitation would likely require user interaction—such as visiting or clicking a crafted link—that triggers the spoofing behavior during page rendering. Given the limited public details, concrete assumptions about the attack path remain speculative, but the moderate score and low EPSS suggest a low probability of widespread exploitation.

Generated by OpenCVE AI on April 7, 2026 at 23:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge on Android to the latest version as soon as it becomes available.

Generated by OpenCVE AI on April 7, 2026 at 23:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft edge Chromium
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:android:*:*
Vendors & Products Microsoft edge Chromium

Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft edge For Android
Vendors & Products Microsoft edge For Android

Sat, 14 Mar 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 22:15:00 +0000

Type Values Removed Values Added
Description Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Title Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge
CPEs cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
Vendors & Products Microsoft
Microsoft edge
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Edge Chromium Edge For Android
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-04-23T15:29:33.113Z

Reserved: 2025-11-13T16:25:14.759Z

Link: CVE-2026-0385

cve-icon Vulnrichment

Updated: 2026-03-14T03:47:47.445Z

cve-icon NVD

Status : Modified

Published: 2026-03-16T14:18:06.797

Modified: 2026-04-07T21:17:00.757

Link: CVE-2026-0385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T20:02:34Z

Weaknesses