Executive brief
A security vulnerability exists in the Microsoft Edge web browser that could allow an attacker to impersonate legitimate websites or services. By exploiting this flaw, a malicious actor could trick users into providing sensitive information or interacting with fraudulent content. This type of spoofing attack can undermine the trust and security of web-based business operations and customer interactions.
Technical details
An improper access control vulnerability (CWE-284) exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw allows a remote, unauthenticated attacker to conduct spoofing attacks over the network. While the attack complexity is rated as high, successful exploitation could lead to a scope change, impacting the integrity and confidentiality of the user's session. The vulnerability was addressed in the security update for version 150.0.4078.48.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication of CVE-2026-58286 by Microsoft and NVD.