Junglewise Threat Intelligence

CVE-2026-58298: Microsoft Edge cross-site scripting and spoofing

CVE-2026-58298 · Severity: high · CVSS 7.2 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a widely used web browser for accessing internet and internal company resources. A vulnerability in how the browser handles web content could allow an attacker to perform spoofing attacks, potentially tricking users into providing sensitive information or interacting with malicious content. This could lead to unauthorized access to user accounts or the theft of login credentials.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Edge (Chromium-based) due to improper neutralization of input during web page generation. An unauthenticated attacker can exploit this over the network to perform spoofing attacks. The vulnerability is tracked as CWE-79 and has a CVSS 3.1 score of 7.2, notably featuring 'Scope: Changed' and requiring no user interaction according to the provided vector. This suggests the flaw may allow an attacker to bypass certain security boundaries within the browser environment. Users should update to version 150.0.4078.48 or later to mitigate this risk.

Affected products

  • Microsoft Edge (Chromium-based) < 150.0.4078.48

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats