Executive brief
Microsoft Edge is a web browser used to access internet and intranet resources. A security flaw in how the browser verifies the source of web content could allow a malicious website to impersonate a legitimate site. This could lead to users being deceived into providing sensitive information or interacting with fraudulent content.
Technical details
A vulnerability classified as an Origin Validation Error (CWE-346) exists in Microsoft Edge (Chromium-based). The flaw stems from improper verification of the source of web content, which can be exploited by a remote, unauthenticated attacker. Exploitation requires user interaction, typically by enticing a victim to visit a specially crafted website. Successful exploitation allows the attacker to perform network-based spoofing, potentially bypassing same-origin policy protections to access or manipulate data across different security domains. Microsoft has addressed this in versions 150.0.4078.99 and later.
Affected products
- Microsoft Edge (Chromium-based) >= 1.0.0.0, < 150.0.4078.99
Timeline
- 2026-07-26: advisory: Initial disclosure by Microsoft and NVD