Impact
The vulnerability is a user interface misrepresentation in Microsoft Edge (Chromium‑based) that allows an attacker to present false information through legitimate browser UI elements. This flaw, categorized as CWE‑451, means that the design incorrectly displays critical information, enabling spoofing that could mislead users into trusting deceptive prompts or sites.
Affected Systems
All builds of Microsoft Edge (Chromium‑based) that have not yet incorporated the CVE‑2026‑45488 fix are potentially affected. The CNA does not specify individual version numbers, so any unpatched installation of Edge falls under the vulnerable scope until an update is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact while the EPSS score of < 1% suggests a very low likelihood of exploitation. The description indicates that the attack requires network delivery of a crafted UI to the browser; based on the description, it is inferred that an adversary could send a malicious web page or similar content to a user’s Edge instance to trigger spoofing. The vulnerability is not listed in campaigns at this time and is not included in CISA’s Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment