Executive brief
A vulnerability in the Microsoft Edge web browser allows an attacker to misrepresent or spoof critical information in the user interface. This could lead a user to believe they are interacting with a legitimate website or security prompt when they are actually being deceived by a malicious actor. Such an exploit could be used to trick users into revealing sensitive information or performing unintended actions.
Technical details
This vulnerability is classified as CWE-451: User Interface (UI) Misrepresentation of Critical Information. It exists in the Chromium-based version of Microsoft Edge, where the browser fails to correctly display or protect critical UI elements. An unauthenticated attacker can exploit this over the network by inducing a user to visit a specially crafted website (User Interaction required). Successful exploitation allows the attacker to spoof content or security indicators, potentially leading to credential theft or further social engineering attacks. Microsoft has addressed this in Edge versions 147.0.3912.60 and later.
Affected products
- Microsoft Edge (Chromium-based) versions up to (excluding) 147.0.3912.60
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory: Microsoft released the initial advisory.
- 2026-04-14: patched: NVD updated with specific affected version information.