Description
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Microsoft Edge (Chromium‑based) enables an unauthorized attacker to perform spoofing over a network. The vulnerability is classified as CWE-284, indicating insufficient authorization checks that may allow an attacker to impersonate another context. While the description does not detail specific packet manipulation, it is inferred that the attacker could craft packets that the browser accepts as originating from a trusted source, potentially leading to the user being misled about the provenance of web content.

Affected Systems

All installations of Microsoft Edge built on Chromium are potentially affected. The CNA list does not specify a narrow version range, so any release of the Chromium‑based Edge might be vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 8.1 classifies the flaw as high severity. The EPSS score is reported as <1%, indicating a very low probability of exploitation at present. The flaw is not yet listed in CISA’s KEV catalog. Because the vulnerability relies on network spoofing, an attacker who can intercept or forge traffic between the Edge client and the network could exploit it, unless mitigated by proper network controls and the official patch.

Generated by OpenCVE AI on July 25, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version via Microsoft Update or the Edge Browser update channel, which addresses the improper access control flaw.
  • Deploy network perimeter controls, such as firewall rules or IDS signatures, to detect and block spoofed packets targeting Microsoft Edge traffic.
  • Enforce strict TLS verification and certificate pinning for trusted connections to reduce the chance that the browser accepts forged data.

Generated by OpenCVE AI on July 25, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T19:35:53.781Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58286

cve-icon Vulnrichment

Updated: 2026-07-07T02:19:31.494Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T21:30:17Z

Weaknesses