Description
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper restriction of rendered UI layers or frames in the Microsoft Bing Search app for iOS, which allows an unauthorized attacker to inject spoofed UI elements that appear legitimate. Based on the description, it is inferred that the attacker could manipulate the rendering of UI layers to deceive users. This flaw, classified as CWE‑1021, can be used to present deceptive content that misleads users into interacting with malicious interfaces, potentially leading to phishing or other social‑engineering attacks. The impact is primarily disclosure of sensitive information or unintended user actions driven by the fabricated UI.

Affected Systems

Affected vendors and products are Microsoft and the Microsoft Bing Search app for iOS. No specific version information is supplied, so the issue likely applies to all current releases of the app until a patch is issued.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is inferred to be the delivery of spoofed UI content over a network path that the mobile device can reach, such as untrusted Wi‑Fi or cellular data. Once rendered, users may unknowingly expose sensitive information or cause unintended app behavior.

Generated by OpenCVE AI on July 31, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Microsoft Bing Search app to the latest version once Microsoft publishes a patch for CVE‑2026‑58595.
  • Apply corporate mobile device management or firewall rules to restrict the app’s outbound connections to trusted networks only, limiting the attacker’s ability to deliver spoofed frames.
  • Enforce HTTPS and app sandboxing on the device to ensure that only encrypted, authenticated traffic is allowed, and consider network segmentation to isolate mobile traffic from potentially malicious sources.

Generated by OpenCVE AI on July 31, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Bing App for IOS Spoofing Vulnerability
First Time appeared Microsoft
Microsoft bing Search
Weaknesses CWE-1021
CPEs cpe:2.3:a:microsoft:bing_search:*:*:*:*:*:ios:*:*
Vendors & Products Microsoft
Microsoft bing Search
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Bing Search
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:46.529Z

Reserved: 2026-07-01T18:03:43.124Z

Link: CVE-2026-58595

cve-icon Vulnrichment

Updated: 2026-07-16T15:39:16.700Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames