Executive brief
Microsoft Edge is a web browser used to access internet and internal corporate resources. A security flaw in the browser's user interface fails to adequately warn users when a dangerous operation is occurring, which could allow an attacker to trick a user into believing they are interacting with a legitimate website or service. This type of spoofing attack can lead to the unauthorized disclosure of sensitive information if a user is misled by the deceptive interface.
Technical details
A spoofing vulnerability exists in Microsoft Edge (Chromium-based) due to insufficient UI warnings for dangerous operations, classified as CWE-357. An unauthenticated attacker can exploit this over the network by inducing a user to visit a specially crafted website or interact with malicious content. The lack of adequate visual cues or warnings allows the attacker to misrepresent interface elements, potentially leading to information disclosure. The vulnerability is addressed in versions 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication by Microsoft and NVD