Description
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft describes an origin validation error in its Chromium-based Edge browser that allows an unauthorized attacker to perform spoofing over a network. That error can cause the browser to accept a forged or manipulated origin header, enabling the creation of a fake site that appears legitimate to the user. The resulting impact is that an attacker could trick a user into interacting with a malicious site that looks authentic, potentially leading to credential theft or other credential-based attacks.

Affected Systems

The affected product is Microsoft Edge built on Chromium, as distributed by Microsoft. No specific version range is listed, so all currently supported releases of Edge that contain the unpatched code are likely vulnerable. Users should verify the version against Microsoft’s update guide and only rely on the advisory for exact version ranges.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity. The vulnerability is listed as not in the CISA KEV catalog, and no EPSS score is available. The likely attack vector is a malicious website or network traffic that a user visits; the attacker must be able to influence the browsing context. If exploited, the attacker could spoof a legitimate domain, potentially causing the user to divulge sensitive information. The risk is therefore significant, especially if the user has administrative access to corporate resources. Mitigation depends on applying the patch before a malicious user can exploit the flaw.

Generated by OpenCVE AI on August 4, 2026 at 09:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest available version, or install the security update that addresses CVE‑2026-66322
  • Apply all Windows security updates that provide Edge patches, ensuring that the operating system is up‑to‑date during the update cycle
  • Implement network‑level controls such as HTTP Strict Transport Security and content security policies to reduce the impact of any remaining origin‑validation flaws, and limit user access to known‑good domains

Generated by OpenCVE AI on August 4, 2026 at 09:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:06:41.058Z

Reserved: 2026-07-24T18:06:51.296Z

Link: CVE-2026-66322

cve-icon Vulnrichment

Updated: 2026-08-04T14:00:38.827Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:39.577

Modified: 2026-08-06T17:08:56.767

Link: CVE-2026-66322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:30:06Z

Weaknesses