Executive brief
Microsoft Edge for iOS is a web browser used to access online services and content on Apple mobile devices. An attacker can craft malicious web content that exploits how the browser handles LLM prompting, allowing them to perform spoofing attacks—such as impersonating legitimate websites or services—and deceive users into disclosing sensitive information or performing unauthorized actions.
Technical details
This vulnerability is an improper neutralization of input used for LLM (Large Language Model) prompting, classified as a prompt injection or similar input-handling flaw. The vulnerability exists in Microsoft Edge for iOS and allows an attacker to inject crafted input that manipulates LLM prompting behavior, enabling spoofing attacks over a network. No specific authentication or elevated privileges are required; an attacker can exploit this via network-accessible content. The attack vector is network-based and does not require user interaction beyond normal browsing. Patches or mitigations should be available through Microsoft's standard security update channels.
Affected products
- Microsoft Edge for iOS <UNKNOWN>
Timeline
- 2026-08-28: disclosed