Impact
An information‑exposure flaw (CWE‑200) in Microsoft Edge (Chromium‑based) lets an attacker spoof a legitimate source over a network, enabling the reading of data that should remain confidential such as cookies, credentials, or local content. The vulnerability, classified as a confidentiality weakness, does not provide code execution or escalation of privileges but risks undermining user privacy by exposing sensitive information.
Affected Systems
All Microsoft Edge (Chromium‑based) installations that have not yet received the security update for CVE‑2026‑56646 are affected. No specific version range has been published, so every current unpatched release remains at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. The most probable attack vector, inferred from the description, is a network‑based spoofing attempt—such as a malicious webpage or DNS manipulation that tricks the browser into treating an untrusted resource as legitimate. Success would allow the attacker to read or capture confidential data from the user’s session without achieving code execution or privilege escalation.
OpenCVE Enrichment