Description
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper control of code generation in Microsoft Edge (Chromium-based) allows an attacker to inject and execute crafted code, leading to spoofing of network traffic. The vulnerability falls under CWE-94 and can enable an unauthorized actor to impersonate legitimate communications, potentially affecting confidentiality and integrity of data exchanged over the network.

Affected Systems

Microsoft Edge (Chromium-based) is the only vendor/product listed, with no specific version information provided in the advisory.

Risk and Exploitability

The CVSS score is 6.1, indicating a medium-impact vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker who can deliver malicious input to the vulnerable component over a network. No specific restrictions on the attacker’s privileges are mentioned, suggesting the exploit could be performed from an external network context if the affected code path is reachable.

Generated by OpenCVE AI on August 4, 2026 at 09:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update available from Microsoft that addresses CVE‑2026‑65804.
  • If an update is not immediately available, block or restrict network traffic that could trigger the vulnerable code generation pathway, such as disabling WebSocket or other dynamic script execution to untrusted domains.
  • Continuously monitor network logs for signs of spoofing or unauthorized code execution and configure alerts for suspicious patterns around the Edge browser.

Generated by OpenCVE AI on August 4, 2026 at 09:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-94
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-24T21:05:20.127Z

Reserved: 2026-07-22T21:36:47.629Z

Link: CVE-2026-65804

cve-icon Vulnrichment

Updated: 2026-08-05T14:29:43.980Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:38.100

Modified: 2026-08-06T16:57:17.183

Link: CVE-2026-65804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:45:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')