Junglewise Threat Intelligence

CVE-2026-70331: Microsoft Edge for iOS prompt injection vulnerability

CVE-2026-70331 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge for iOS is a web browser used to access online services and content on Apple mobile devices. An attacker can craft malicious web content that exploits how the browser handles LLM prompting, allowing them to perform spoofing attacks—such as impersonating legitimate websites or services—and deceive users into disclosing sensitive information or performing unauthorized actions.

Technical details

This vulnerability is an improper neutralization of input used for LLM (Large Language Model) prompting, classified as a prompt injection or similar input-handling flaw. The vulnerability exists in Microsoft Edge for iOS and allows an attacker to inject crafted input that manipulates LLM prompting behavior, enabling spoofing attacks over a network. No specific authentication or elevated privileges are required; an attacker can exploit this via network-accessible content. The attack vector is network-based and does not require user interaction beyond normal browsing. Patches or mitigations should be available through Microsoft's standard security update channels.

Affected products

  • Microsoft Edge for iOS <UNKNOWN>

Timeline

  • 2026-08-28: disclosed

References

Related threats