Junglewise Threat Intelligence

CVE-2026-32208: Microsoft Edge cross-site scripting and spoofing

CVE-2026-32208 · Severity: high · CVSS 8.8 · Published 2026-06-19

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge, a widely used web browser, contains a security vulnerability that could allow an attacker to impersonate legitimate content or services. An authorized attacker could exploit this flaw to spoof web pages, potentially leading to the theft of sensitive user information or unauthorized access to corporate data. This poses a risk to organizational reputation and data integrity if users are misled by fraudulent content within the browser.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Edge (Chromium-based) due to improper neutralization of input during web page generation. An attacker with basic user authorization (PR:L) can exploit this flaw over a network without requiring user interaction (UI:N). Successful exploitation allows the attacker to perform spoofing attacks, potentially leading to full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) within the context of the affected browser session. Users are advised to apply the latest security updates from Microsoft to mitigate this risk.

Affected products

  • Microsoft Edge (Chromium-based) All versions

Timeline

  • 2026-06-19: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats