Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper neutralization of user input when Microsoft Edge (Chromium‑based) constructs web pages, creating a cross‑site scripting weakness classified as CWE‑79. An attacker can inject malicious content that modifies the DOM presented to the user, resulting in spoofed page appearance. The flaw permits an unauthorized party to display false information to a user while they view a site, thereby enabling spoofing over the network.

Affected Systems

All Microsoft Edge (Chromium‑based) installations are potentially vulnerable; the CVE does not specify a particular version range, so any current installation may be affected.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate‑to‑high severity, while an EPSS score of less than 1% signals a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a malicious or compromised web page that delivers crafted script content to a user’s browser, allowing the attacker to alter the displayed page. Exploitation requires user interaction with such content and is limited to browsers that have not yet been patched.

Generated by OpenCVE AI on August 1, 2026 at 20:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest available version from Microsoft’s Security Response Center.
  • Enable the browser’s strict tracking prevention and configure a restrictive content‑security policy to limit script execution.
  • Disable or restrict scripting on untrusted or unknown sites via browser settings, if available.

Generated by OpenCVE AI on August 1, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:44.130Z

Reserved: 2026-06-26T17:45:44.853Z

Link: CVE-2026-57977

cve-icon Vulnrichment

Updated: 2026-07-06T16:32:42.264Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:01.193

Modified: 2026-07-07T13:14:18.280

Link: CVE-2026-57977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')