Junglewise Threat Intelligence

CVE-2026-58286: Microsoft Edge improper access control spoofing vulnerability

CVE-2026-58286 · Severity: high · CVSS 8.1 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Edge web browser that could allow an attacker to impersonate legitimate websites or services. By exploiting this flaw, a malicious actor could trick users into providing sensitive information or interacting with fraudulent content. This type of spoofing attack can undermine the trust and security of web-based business operations and customer interactions.

Technical details

An improper access control vulnerability (CWE-284) exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw allows a remote, unauthenticated attacker to conduct spoofing attacks over the network. While the attack complexity is rated as high, successful exploitation could lead to a scope change, impacting the integrity and confidentiality of the user's session. The vulnerability was addressed in the security update for version 150.0.4078.48.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial publication of CVE-2026-58286 by Microsoft and NVD.

References

Related threats