Junglewise Threat Intelligence

CVE-2026-42891: Microsoft Edge UI misrepresentation spoofing vulnerability

CVE-2026-42891 · Severity: medium · CVSS 6.5 · Published 2026-05-12

Technologies: Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used to access the internet and internal corporate applications. A vulnerability in the browser's user interface could allow an attacker to misrepresent critical information, such as security indicators or website identities. This could lead to users being deceived into providing sensitive information to a malicious site that appears legitimate.

Technical details

A vulnerability exists in Microsoft Edge (Chromium-based) due to the misrepresentation of critical information within the User Interface (UI), classified as CWE-451. An unauthenticated attacker can exploit this over the network to perform spoofing attacks. The attack complexity is rated as high, suggesting that specific conditions or timing may be required to successfully deceive the user. Successful exploitation could allow an attacker to compromise the confidentiality of user data by tricking them into interacting with a spoofed interface. Microsoft has released information regarding this vulnerability in their security update guide.

Affected products

  • Microsoft Edge (Chromium-based)

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats