Description
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-26
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. This flaw enables an attacker to make the browser believe that a network resource is trusted when it is not, potentially leading to phishing, credential theft, or other attacks that rely on spoofed identities. The vulnerability is classified as CWE‑346, indicating an insecurity in how the origin of a resource is verified. The CVSS score of 5.4 indicates a moderate severity, primarily impacting confidentiality and integrity through impersonation rather than granting arbitrary code execution.

Affected Systems

Microsoft Edge (Chromium-based) as supplied by Microsoft. No specific version range is listed in the current advisory, so all currently supported releases of this browser are potentially impacted.

Risk and Exploitability

An EPSS score of 0.00216 indicates a very low probability of exploitation, showing that no large‑scale exploit campaigns have been observed. Nevertheless, the origin validation flaw can be exploited via network traffic that an Edge instance processes, meaning a remote attacker who can influence the traffic or supply crafted network packets could trigger the spoofing behavior. The moderate CVSS score reflects the potential damage to user identity assurance, but there are no known privileges or capabilities beyond the spoofed identity that are currently promised by the description.

Generated by OpenCVE AI on August 3, 2026 at 18:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy DNSSEC and certificate transparency to reduce the success rate of spoofed network resources.
  • Keep Microsoft Edge configured to install updates automatically and enable its built‑in safe‑browsing features to provide early detection of spoofing attempts.
  • Monitor inbound and outbound network traffic for repeated origin spoofing patterns and investigate anomalous sessions promptly.

Generated by OpenCVE AI on August 3, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-14T17:21:04.272Z

Reserved: 2026-06-26T17:45:44.853Z

Link: CVE-2026-57978

cve-icon Vulnrichment

Updated: 2026-07-27T17:24:11.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-26T18:18:23.780

Modified: 2026-08-03T14:56:36.670

Link: CVE-2026-57978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:15:04Z

Weaknesses