Microsoft Edge (Chromium-based) Server-Side Request Forgery Vulnerability Allowing Spoofing

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Microsoft Edge (Chromium-based) version 150.0.4078.48. This vulnerability allows an unauthorized attacker to perform network spoofing. Exploitation would require convincing a user to visit a malicious website, where the vulnerability could be triggered through user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized network spoofing.

Reproduction

To reproduce this vulnerability, a user must be convinced to visit a specially crafted website using the vulnerable version of Microsoft Edge. Once on the site, the user must perform two tap gestures to activate the autofill feature, which can be exploited due to the SSRF vulnerability.

Remediation

Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48 through the Microsoft Update Catalog.

Added: Jul 3, 2026, 9:39 PM
Updated: Jul 3, 2026, 9:39 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.4
exploitability
4.0
remediation
7.7
relevance
8.4
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.