Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw in the browser's access controls could allow an attacker to impersonate legitimate websites or services. This type of spoofing attack can be used to trick users into providing sensitive information or to bypass security warnings, potentially leading to data theft or unauthorized access to user accounts.
Technical details
An improper access control vulnerability (CWE-284) exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw allows a remote, unauthenticated attacker to perform network-based spoofing. While the attack complexity is rated as high, the vulnerability has a scope change impact, meaning it could potentially affect components beyond the browser itself. Successful exploitation could allow an attacker to misrepresent web content or security indicators, leading to a loss of integrity and limited confidentiality/availability impacts. Users are advised to update to the latest version of Microsoft Edge to mitigate this risk.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication by Microsoft and NVD.