Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw arises from improper neutralization of input during web page generation, which introduces a cross‑site scripting weakness in Microsoft Edge (Chromium‑based). By injecting crafted content, an attacker can alter the browser’s DOM to display false or manipulated information, leading to spoofing over the network. The vulnerability permits attackers to mislead users about the authenticity of a web page, potentially opening the door for phishing or other social‑engineering attacks.

Affected Systems

The vulnerability applies to all Microsoft Edge (Chromium‑based) browsers; no specific version range is listed, so any current installation is potentially vulnerable.

Risk and Exploitability

A CVSS score of 7.1 reflects moderate‑to‑high severity, while an EPSS score of < 1% indicates a low likelihood of exploitation in the wild. The flaw is not currently listed in CISA’s KEV catalog. The likely attack vector is a malicious or compromised web page that delivers crafted script content to a user’s browser, enabling spoofing. Though exploitation is technically possible, attackers may opt for targeted attacks given the low EPSS score.

Generated by OpenCVE AI on July 21, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest available version from Microsoft’s Security Response Center.
  • Enable the browser’s strict tracking prevention and configure a restrictive content‑security policy to limit script execution.
  • Educate users to verify the authenticity of web pages before interacting with unfamiliar content.

Generated by OpenCVE AI on July 21, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:34:21.336Z

Reserved: 2026-06-26T17:45:44.853Z

Link: CVE-2026-57977

cve-icon Vulnrichment

Updated: 2026-07-06T16:32:42.264Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')