Executive brief
A vulnerability in Microsoft Edge could allow a malicious website to misrepresent or hide critical security information in the browser's user interface. This could lead a user to believe they are interacting with a legitimate site or security prompt when they are actually being targeted by a spoofing attack. Successful exploitation could result in users being tricked into performing unintended actions or disclosing information to a fraudulent site.
Technical details
A vulnerability classified as CWE-451 (User Interface Misrepresentation of Critical Information) exists in Microsoft Edge (Chromium-based). The flaw allows a remote, unauthenticated attacker to manipulate how critical information is displayed in the browser UI, facilitating spoofing attacks. Exploitation requires a user to visit a specially crafted website (User Interaction required). According to the CVSS vector, the attack has low complexity and can be executed over the network, potentially leading to a loss of integrity but not confidentiality or availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Edge (Chromium-based)
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory