Microsoft Edge (Chromium-based) Server-Side Request Forgery Vulnerability Allowing Spoofing

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Microsoft Edge (Chromium-based) version 150.0.4078.48. This vulnerability allows an unauthorized attacker to perform spoofing over a network. The issue arises from the way the browser handles certain requests, potentially allowing attackers to manipulate server interactions.

Impact

Exploitation of this vulnerability could lead to unauthorized network spoofing, allowing attackers to impersonate other entities or services.

Reproduction

To exploit this vulnerability, an attacker could host a specially crafted website designed to take advantage of the SSRF flaw in Microsoft Edge. The attacker would need to convince a user to visit the website, such as through an email or message enticement, or by sending an attachment that prompts the user to open it.

Remediation

Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48 from the Microsoft Edge Security Update page.

Added: Jul 3, 2026, 9:41 PM
Updated: Jul 3, 2026, 9:41 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.4
exploitability
4.0
remediation
7.7
relevance
8.8
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.