Executive brief
Microsoft Edge is a web browser used to access internet and internal corporate resources. A vulnerability in the browser's user interface allows an attacker to misrepresent or hide critical information, such as the true identity of a website. This could lead to users being tricked into providing sensitive information to a fraudulent site that appears legitimate, potentially resulting in credential theft or data exposure.
Technical details
A spoofing vulnerability exists in Microsoft Edge (Chromium-based) due to the misrepresentation of critical information in the User Interface (CWE-451). An unauthorized attacker can exploit this over the network by convincing a user to visit a specially crafted website. Successful exploitation allows the attacker to spoof web content or security indicators, potentially leading to a loss of confidentiality. The vulnerability is addressed in Microsoft Edge versions 147.0.3912.60 and later.
Affected products
- Microsoft Edge (Chromium-based) < 147.0.3912.60
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory: Initial advisory published by Microsoft
- 2026-06-17: patched: Patch information confirmed in update guide