Description
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published: 2026-05-18
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to manipulate or deceive users by presenting forged or modified content within Microsoft Edge (Chromium-based). The flaw is a classic example of an injection weakness that can render false information or phishing interfaces convincing, potentially leading to credential theft or malicious downloads. The associated CWE-79 indicates an underlying cross‑site scripting weakness that breaches user intent and trust.

Affected Systems

Microsoft Edge (Chromium-based) is affected. No specific version information is listed, so any installation of the Chromium‑based Edge product may be at risk until an official patch is applied.

Risk and Exploitability

The CVSS score of 5.4 reflects a moderate severity: exploitation does not provide remote code execution or privilege escalation, but it can still significantly compromise user security by deception. The EPSS score is unavailable, so current exploitation probability cannot be precisely quantified, and the flaw is not yet listed in the CISA KEV catalog. Inferred from the description, the attack likely requires a user to visit a malicious web page, where the injected content can subvert the browser’s rendering to display spoofed information. Without a documented exploit, the risk remains primarily from targeted phishing campaigns.

Generated by OpenCVE AI on May 18, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that addresses the spoofing flaw
  • Enable Microsoft Defender SmartScreen and enable cloud‑based filtering to block malicious sites
  • Configure Edge’s security settings to enforce strict certificate validation and block sites with untrusted certificates

Generated by OpenCVE AI on May 18, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 18 May 2026 17:45:00 +0000

Type Values Removed Values Added
Description Microsoft Edge (Chromium-based) Spoofing Vulnerability
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-05-18T18:10:09.157Z

Reserved: 2026-05-12T16:07:22.618Z

Link: CVE-2026-45494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-18T18:17:38.390

Modified: 2026-05-18T19:32:38.777

Link: CVE-2026-45494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-18T21:00:13Z

Weaknesses