Junglewise Threat Intelligence

CVE-2026-45650: Microsoft Bing UI misrepresentation spoofing vulnerability

CVE-2026-45650 · Severity: medium · CVSS 4.3 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

Microsoft Bing is a web-based search engine used to find information and services online. A vulnerability in its user interface could allow an attacker to misrepresent critical information, potentially tricking users into believing they are interacting with a legitimate site or service. This type of spoofing can lead to the unauthorized disclosure of sensitive information if a user is misled by the falsified interface.

Technical details

A vulnerability classified as CWE-451 (User Interface Misrepresentation of Critical Information) exists in Microsoft Bing. The flaw allows a remote, unauthenticated attacker to spoof interface elements over the network, potentially leading to information disclosure. Exploitation requires user interaction, typically involving a victim visiting a malicious link or viewing crafted content that triggers the UI misrepresentation. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting low impact on confidentiality and no impact on integrity or availability. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Bing

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats