Junglewise Threat Intelligence

CVE-2026-45488: Microsoft Edge UI misrepresentation spoofing vulnerability

CVE-2026-45488 · Severity: medium · CVSS 5.4 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used to access internet and internal corporate resources. A vulnerability in how the browser displays information allows an attacker to trick users by misrepresenting critical interface elements, such as security indicators or website addresses. This could lead to users providing sensitive information to a fraudulent website or performing actions they believe are safe.

Technical details

A vulnerability classified as CWE-451 (User Interface Misrepresentation of Critical Information) exists in Microsoft Edge (Chromium-based). The flaw allows a remote, unauthenticated attacker to misrepresent critical UI elements over a network. Exploitation requires user interaction, typically involving a victim visiting a specially crafted website. Successful exploitation allows the attacker to perform spoofing, potentially leading to a loss of confidentiality and integrity. Microsoft has addressed this in versions 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 < 150.0.4078.48

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats