Junglewise Threat Intelligence

CVE-2026-45489: Microsoft Edge Chromium-based spoofing vulnerability

CVE-2026-45489 · Severity: medium · CVSS 6.5 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used for accessing internet and internal corporate resources. A spoofing vulnerability has been identified that could allow an attacker to misrepresent web content or identity to a user. If exploited, this could lead to users being deceived into providing sensitive information or interacting with malicious sites under the guise of a trusted source.

Technical details

A spoofing vulnerability exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw allows a remote, unauthenticated attacker to misrepresent information or the origin of content within the browser interface. Exploitation requires a user to visit a specially crafted website (User Interaction required). According to the CVSS vector, the primary impact is on confidentiality, suggesting the spoofing may be used to exfiltrate data or deceive the user into revealing sensitive information. Microsoft has released updates to address this issue.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial publication by Microsoft and NVD

References

Related threats