Impact
The vulnerability allows an attacker to manipulate Microsoft Edge’s user interface so that security indicators or other UI elements display falsified information. This misrepresentation can lead users to trust malicious content, making the flaw primarily a vector for phishing or other social‑engineering attacks. The weakness is classified as CWE‑749 for improper filtering of UI elements and CWE‑290 for information leakage through user‑trusted UI.
Affected Systems
Microsoft Edge (Chromium-based) releases that exhibit the discussed spoofing flaw are presumed widely vulnerable; the advisory specifies no version boundary, so all maintained releases should be treated as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of <1% shows a low exploitation probability at the moment, and the flaw is not listed in CISA KEV. Based on the description and typical behavior of spoofing flaws in browsers, the likely attack vector is remote: an attacker hosts malicious content that exploits the UI rendering path when a user visits the site, with no special privileges or local code execution required.
OpenCVE Enrichment