Description
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published: 2026-07-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits an attacker to cause Microsoft Edge (Chromium-based) to display falsified security indicators or other user interface elements that misrepresent the trustworthiness of a web page. The primary impact is user deception, which can facilitate phishing attacks and other social‑engineering tactics. The weakness aligns with authorization bypass (CWE‑290) and improper filtering of UI elements (CWE‑749).

Affected Systems

Microsoft Edge (Chromium-based) is the affected product. The advisory does not specify particular builds, indicating that all current releases of the browser are potentially vulnerable. No version restrictions are listed, so administrators should assume all supported versions are impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not included in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote, involving a user navigating to a malicious web page; no other prerequisites are noted.

Generated by OpenCVE AI on July 23, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge security update as published in the MSRC advisory, which resolves the spoofing weakness.
  • Configure group policy or browser settings to block or disable extensions that can alter security indicator UI elements, limiting the opportunity for spoofing.
  • Educate users to verify the authenticity of browser security indicators and to be cautious of unexpected prompts, reducing the risk of falling for spoofed UI.

Generated by OpenCVE AI on July 23, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 12 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-749

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Tue, 07 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290

Tue, 07 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Mon, 06 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-79

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sun, 05 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sat, 04 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Sat, 04 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Microsoft Edge (Chromium-based) Spoofing Vulnerability
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:55:15.748Z

Reserved: 2026-05-12T16:07:22.618Z

Link: CVE-2026-45489

cve-icon Vulnrichment

Updated: 2026-07-06T16:47:37.836Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T16:15:03Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-749

    Exposed Dangerous Method or Function