Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation in Microsoft Edge (Chromium‑based) creates a cross‑site scripting flaw (CWE‑79). An attacker who delivers crafted web content can cause the browser to render malicious input, allowing the attacker to manipulate UI elements, prompts, or messages to deceive users into believing they are interacting with legitimate interfaces. This can lead to the disclosure of sensitive information or the execution of unintended actions.

Affected Systems

Microsoft Edge (Chromium‑based) is potentially impacted; no specific versions are disclosed, so any current unpatched release could be vulnerable. The advisory links Microsoft’s update guide for available patches.

Risk and Exploitability

The CVSS score of 5.4 indicates medium severity. The EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the delivery of malicious or compromised web content over a network to the browser, requiring the user to load a page containing the crafted input before the exploit is successful.

Generated by OpenCVE AI on July 21, 2026 at 09:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update from Microsoft’s update guide to address CVE‑2026‑58524
  • Configure Edge to enforce strict content‑security policies or use extensions that restrict inline scripting
  • Enable Microsoft Defender SmartScreen or an equivalent safe‑browsing feature to help detect malicious sites

Generated by OpenCVE AI on July 21, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:46.887Z

Reserved: 2026-07-01T04:33:41.869Z

Link: CVE-2026-58524

cve-icon Vulnrichment

Updated: 2026-07-06T15:16:14.132Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')