Junglewise Threat Intelligence

CVE-2026-56646: Microsoft Edge information disclosure and spoofing

CVE-2026-56646 · Severity: medium · CVSS 6.5 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

A security vulnerability in the Microsoft Edge web browser could allow an unauthorized attacker to access sensitive information. By tricking a user into visiting a malicious website or clicking a link, an attacker can perform spoofing attacks, potentially leading to the theft of private data or session information. This could compromise user privacy and allow attackers to impersonate legitimate services within the browser environment.

Technical details

This vulnerability is classified as an Exposure of Sensitive Information (CWE-200) within Microsoft Edge (Chromium-based). The flaw allows an unauthenticated, remote attacker to perform spoofing over a network by leveraging improper information handling. Exploitation requires user interaction, typically involving a victim navigating to a specially crafted URL or website. Successful exploitation results in high confidentiality impact, allowing the attacker to view data they are not authorized to access. Microsoft has addressed this in version 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) < 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats