Junglewise Threat Intelligence

CVE-2026-45494: Microsoft Edge Chromium-based spoofing vulnerability

CVE-2026-45494 · Severity: medium · CVSS 5.4 · Published 2026-05-18

Technologies: Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used to access the internet and internal corporate applications. A spoofing vulnerability has been identified that could allow an attacker to misrepresent web content or identity to a user. If exploited, this could lead to users being deceived into providing sensitive information or performing unintended actions on a malicious website that appears legitimate.

Technical details

A spoofing vulnerability exists in Microsoft Edge (Chromium-based) due to improper neutralization of input during web page generation, classified as CWE-79 (Cross-site Scripting). The vulnerability is reachable over the network and requires no special privileges, though it does require user interaction, such as a user visiting a malicious website. An attacker who successfully exploited this vulnerability could spoof content or perform unauthorized actions in the context of the user's browser session. Microsoft has released information regarding this vulnerability in their Security Update Guide.

Affected products

  • Microsoft Edge (Chromium-based)

Timeline

  • 2026-05-18: disclosed: Initial disclosure by Microsoft
  • 2026-05-18: advisory: NVD record published

References

Related threats