Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting resulting in spoofing over a network
Action: Patch Now
AI Analysis

Impact

The vulnerability is an improper neutralization of user‑provided input during web page generation, which is a classic cross‑site scripting weakness. An attacker can exploit this flaw to inject malicious scripts that cause a web page or application to appear as though it originates from a other sensitive information. The vulnerability does not provide direct code execution or arbitrary data access; its primary impact is graphical or content spoofing via injected malicious content.

Affected Systems

Microsoft Edge (Chromium‑based) is the affected product. The CVE does not specify any particular release or build numbers, so all versions of the Chromium‑based Edge browser are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 6.1 places this bug EPSS score is less than 1%, indicating a low probability of page content, the risk is higher in environments where internal networks allow users to view untrusted web content. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread, actively exploited instances have been reported yet, but the existence of the flaw warrants immediate remediation to prevent potential spoofing incidents.

Generated by OpenCVE AI on September 21, 2026 at 03:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Microsoft Edge to the latest patched version as issued by Microsoft.
  • Configure enterprise group policy or browser security settings to monitor or block the loading of untrusted web content that could contain malicious injections.
  • Enable logging and monitoring for content injection events or unusual page rendering behaviors to detect and respond to any attempted spoofing.

Generated by OpenCVE AI on September 21, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-01T22:52:39.896Z

Reserved: 2026-08-20T20:11:33.673Z

Link: CVE-2026-77490

cve-icon Vulnrichment

Updated: 2026-09-11T20:07:44.965Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T20:18:45.403

Modified: 2026-09-25T20:41:43.903

Link: CVE-2026-77490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')