Executive brief
A vulnerability in the Microsoft Edge browser for Android devices could allow an attacker to misrepresent critical information in the user interface. This could be used to trick users into believing they are interacting with a legitimate website or service when they are actually on a malicious one. Such spoofing attacks are often used to steal login credentials or other sensitive personal information.
Technical details
A vulnerability classified as CWE-451 (User Interface Misrepresentation of Critical Information) exists in Microsoft Edge for Android. The flaw allows a remote, unauthenticated attacker to manipulate how critical information is displayed to the user over a network. Exploitation requires user interaction, typically involving a victim visiting a specially crafted website. Successful exploitation enables the attacker to perform spoofing, potentially leading to the disclosure of sensitive information if the user is misled by the misrepresented UI elements.
Affected products
- Microsoft Edge for Android
Timeline
- 2026-05-12: disclosed: Initial publication of the CVE record.
- 2026-05-12: advisory: Microsoft released the security update guide for this vulnerability.