Junglewise Threat Intelligence

CVE-2026-77490: Microsoft Edge cross-site scripting in page generation

CVE-2026-77490 · Severity: medium · CVSS 6.1 · Published 2026-09-11

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions to access the internet and corporate web applications. This vulnerability allows an attacker to inject malicious scripts into web pages, potentially enabling account takeover, credential theft, or malware distribution through spoofed or fraudulent web content. The attack can occur through network-based vectors without requiring special privileges.

Technical details

This is a cross-site scripting (XSS) vulnerability in Microsoft Edge's (Chromium-based) web page generation logic. The root cause is improper neutralization of user-controlled input during HTML rendering, allowing an attacker to inject arbitrary JavaScript code that executes in the browser context. The vulnerability requires network access and likely user interaction (visiting a malicious or compromised website); an attacker can achieve arbitrary script execution in the victim's browser with the same privileges as the user. Patches are expected through Microsoft's standard security update process.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-09-11: disclosed

References

Related threats