Description
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-03
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability originates from an origin validation error that allows an unauthorized attacker to spoof source identities over a network. The flaw is categorized as CWE‑346, a weakness that undermines authenticity by permitting an attacker to forge an origin header, potentially leading to deceptive communications or impersonation of legitimate services.

Affected Systems

Microsoft Edge (Chromium‑based) is affected. No specific version information is provided, so all current releases of this browser could be impacted until a fix is released.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate risk, and the EPSS score is not available, making it unclear how frequently the vulnerability is actively exploited. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would require an attacker to send crafted network traffic that bypasses the browser’s origin validation, enabling spoofed content or connections to appear as legitimate sources.

Generated by OpenCVE AI on August 4, 2026 at 09:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that contains the fix for this origin validation error.
  • Configure browsers and network devices to enforce strict origin verification and reject packets with mismatched origin headers.
  • Implement network monitoring to detect anomalous origin addresses and use intrusion detection systems to alert on possible spoofing attempts.

Generated by OpenCVE AI on August 4, 2026 at 09:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Edge (chromium-based)
Vendors & Products Microsoft microsoft Edge (chromium-based)

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium Microsoft Edge (chromium-based)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:02:06.259Z

Reserved: 2026-07-24T18:06:51.295Z

Link: CVE-2026-66316

cve-icon Vulnrichment

Updated: 2026-08-04T14:19:49.553Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:39.060

Modified: 2026-08-06T17:04:28.910

Link: CVE-2026-66316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:24Z

Weaknesses