Executive brief
Microsoft Edge, the company's web browser, contains a flaw that allows attackers to manipulate file paths and names, potentially leading to spoofing attacks where users are tricked into accessing malicious content. An attacker can exploit this over a network without authentication, compromising user trust in the browser's security indicators.
Technical details
The vulnerability is classified as external control of file name or path (CWE-434/CWE-22 class), affecting the Chromium-based Microsoft Edge browser. The flaw permits an attacker to influence file path or name handling, enabling spoofing attacks delivered over a network. Attack vector is network-based with no authentication required. An attacker can craft malicious requests to trick users into believing they are accessing legitimate content when in fact they are viewing attacker-controlled resources. Patches are available through Microsoft Security Updates.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-28: disclosed