Description
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Microsoft Edge (Chromium‑based) permits an unauthorized attacker to spoof network traffic that the browser interprets as originating from a trusted source. Classified as CWE‑284, the flaw indicates an absence of sufficient authorization checks in the handling of network data. The impact is that users may be led to believe that content comes from a legitimate origin while it has been tampered with, potentially enabling phishing or data injection attacks.

Affected Systems

All installations of Microsoft Edge built on Chromium are potentially vulnerable. The CNA does not limit affected releases, so any current version may be impacted.

Risk and Exploitability

The CVSS v3.1 score of 8.1 signals high severity. The EPSS score of <1% indicates a very low likelihood of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is forging or intercepting network packets that are sent to or from the Edge client; this inference is drawn from the term "spoofing over a network" as the vulnerability falls under missing authorization when processing inbound traffic. Exploitation would require the ability to manipulate network traffic between a user’s machine and the destination of the Edge browser.

Generated by OpenCVE AI on August 12, 2026 at 10:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update via Windows Update.
  • Configure the organization’s firewall or IDS/IPS to detect and block spoofed packets originating from or targeting the Edge client.
  • Enforce HTTPS-only browsing in Edge using Enterprise Policies to prevent the browser from accepting untrusted or spoofed content.

Generated by OpenCVE AI on August 12, 2026 at 10:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-14T17:25:23.782Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58286

cve-icon Vulnrichment

Updated: 2026-07-07T02:19:31.494Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:03.293

Modified: 2026-07-07T04:17:55.037

Link: CVE-2026-58286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T10:15:02Z

Weaknesses