Executive brief
Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to trick users into viewing fraudulent content. By exploiting this vulnerability, a malicious actor could perform 'spoofing' attacks, potentially leading to the theft of sensitive information or unauthorized actions on behalf of the user. This issue requires the user to interact with a malicious link or website to be successful.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Edge (Chromium-based) due to improper neutralization of input during web page generation. An unauthenticated attacker can exploit this by convincing a user to visit a specially crafted website or click a malicious link (User Interaction required). Successful exploitation allows the attacker to perform spoofing attacks and potentially execute arbitrary script in the context of the user's browser session. The vulnerability is addressed in versions starting from 150.0.4078.48.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: NVD and Microsoft published the vulnerability details.
- 2026-07-03: patched: Fixes available in version 150.0.4078.48 and later.