Description
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper access control in Microsoft Edge’s Chromium core that enables an attacker to spoof network identities. This can allow a malicious host to masquerade as a legitimate server and redirect or inject traffic into a browser session, undermining the authenticity of network communications. The vulnerability does not grant arbitrary code execution or system compromise but does expose users to phishing or man‑in‑the‑middle attacks.

Affected Systems

Microsoft Edge (Chromium-based) browsers are affected. No specific release numbers are listed, so all current public releases remain vulnerable until an official Microsoft update is applied.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity issue, while the EPSS score of <1% reflects a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based; an untrusted party could send a crafted page or manipulate traffic between the browser and remote servers to trigger the spoofing behavior.

Generated by OpenCVE AI on July 21, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest fix.
  • Configure group policy or local security settings to enforce strict server identity validation or disable features that allow spoofing.
  • Deploy network perimeter defenses such as IDS/IPS to detect spoofing attempts and enforce strict transport security (HSTS) or certificate pinning to reduce the risk of exploitation.

Generated by OpenCVE AI on July 21, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:35.529Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58282

cve-icon Vulnrichment

Updated: 2026-07-06T14:27:39.334Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses