Microsoft Edge (Chromium-based) Cross-Site Scripting Vulnerability Allowing Spoofing

Vulnerability

A cross-site scripting vulnerability has been identified in Microsoft Edge (Chromium-based) version 150.0.4078.48. This issue arises from improper input neutralization during web page generation, allowing an unauthorized attacker to perform spoofing over the network. Exploitation of this vulnerability could lead to the attacker reading information from the victim's browser related to the vulnerable URL, which could then be sent to them.

Impact

Exploitation of this vulnerability could result in spoofing attacks, with an attacker potentially reading sensitive information from the victim's browser and sending it to themselves.

Reproduction

To reproduce this vulnerability, an attacker would need to host a specially crafted website designed to exploit the cross-site scripting flaw. They would then have to convince a user to visit the site, such as through an email or instant message enticement, or by sending an attachment that prompts the user to open it.

Remediation

Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48 from the Microsoft Update Catalog.

Added: Jul 3, 2026, 9:23 PM
Updated: Jul 3, 2026, 9:23 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
4.6
remediation
7.7
relevance
8.7
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.