Description
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a user interface misrepresentation in Microsoft Edge (Chromium‑based) that allows an attacker to present false information through legitimate browser UI elements. This flaw, categorized as CWE‑451, means that the design incorrectly displays critical information, enabling spoofing that could mislead users into trusting deceptive prompts or sites.

Affected Systems

All builds of Microsoft Edge (Chromium‑based) that have not yet incorporated the CVE‑2026‑45488 fix are potentially affected. The CNA does not specify individual version numbers, so any unpatched installation of Edge falls under the vulnerable scope until an update is applied.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact while the EPSS score of < 1% suggests a very low likelihood of exploitation. The description indicates that the attack requires network delivery of a crafted UI to the browser; based on the description, it is inferred that an adversary could send a malicious web page or similar content to a user’s Edge instance to trigger spoofing. The vulnerability is not listed in campaigns at this time and is not included in CISA’s Known Exploited Vulnerabilities catalog.

Generated by OpenCVE AI on July 25, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge security update that resolves the interface spoofing flaw identified as CWE‑451. This patch corrects the incorrect presentation of critical information.
  • Ensure Microsoft Edge auto‑updates are enabled, or manually install the newest release from the Stable or Enterprise channel, so the fix is deployed promptly.
  • Educate users to verify that browser UI elements such as security prompts or login dialogs match the expected branding and URLs before interacting, to mitigate spoofing risks.

Generated by OpenCVE AI on July 25, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-451
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T19:30:35.176Z

Reserved: 2026-05-12T16:07:22.617Z

Link: CVE-2026-45488

cve-icon Vulnrichment

Updated: 2026-07-07T02:18:12.436Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T21:30:17Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information