Description
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published: 2026-07-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to manipulate Microsoft Edge’s user interface so that security indicators or other UI elements display falsified information. This misrepresentation can lead users to trust malicious content, making the flaw primarily a vector for phishing or other social‑engineering attacks. The weakness is classified as CWE‑749 for improper filtering of UI elements and CWE‑290 for information leakage through user‑trusted UI.

Affected Systems

Microsoft Edge (Chromium-based) releases that exhibit the discussed spoofing flaw are presumed widely vulnerable; the advisory specifies no version boundary, so all maintained releases should be treated as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. The EPSS score of <1% shows a low exploitation probability at the moment, and the flaw is not listed in CISA KEV. Based on the description and typical behavior of spoofing flaws in browsers, the likely attack vector is remote: an attacker hosts malicious content that exploits the UI rendering path when a user visits the site, with no special privileges or local code execution required.

Generated by OpenCVE AI on August 1, 2026 at 19:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge security update as released in the MSRC advisory, which removes the ability to alter security indicator UI elements.
  • Enforce group‑policy or browser settings that block or restrict extensions capable of modifying UI indicators, thereby reducing the attack surface.
  • Educate users to verify genuine browser security indicators and remain vigilant against unexpected prompts or UI changes to mitigate the risk of falling for spoofed interfaces.

Generated by OpenCVE AI on August 1, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 12 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-749

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Tue, 07 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290

Tue, 07 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Mon, 06 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 05 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sat, 04 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sat, 04 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Microsoft Edge (Chromium-based) Spoofing Vulnerability
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:15:13.257Z

Reserved: 2026-05-12T16:07:22.618Z

Link: CVE-2026-45489

cve-icon Vulnrichment

Updated: 2026-07-06T16:47:37.836Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T21:17:00.307

Modified: 2026-07-12T20:16:18.723

Link: CVE-2026-45489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:00:07Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-749

    Exposed Dangerous Method or Function