PatchSiren cyber security CVE debrief
CVE-2026-45494 Microsoft CVE debrief
A spoofing vulnerability in Microsoft Edge (Chromium-based) allows an attacker to manipulate UI elements to deceive users. The vulnerability has a CVSS 3.1 score of 5.4 (Medium severity) and is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). Affected versions are prior to 148.0.3967.70. Microsoft has released a security update addressing this issue.
- Vendor
- Microsoft
- Product
- Microsoft Edge (Chromium-based)
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-05-19
Who should care
End users and enterprise administrators running Microsoft Edge (Chromium-based) versions prior to 148.0.3967.70. Organizations with managed browser deployments should prioritize this update to prevent potential phishing or credential harvesting attacks leveraging spoofed UI elements.
Technical summary
This vulnerability in Microsoft Edge (Chromium-based) enables UI spoofing attacks where malicious content could be rendered to appear as legitimate browser interface elements. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N) indicates network attack vector, low attack complexity, no privileges required, but requires user interaction. The confidentiality and integrity impacts are low, with no availability impact. The underlying weakness is CWE-79, typically associated with cross-site scripting contexts where input sanitization failures allow injection of malicious content.
Defensive priority
medium
Recommended defensive actions
- Update Microsoft Edge to version 148.0.3967.70 or later
- Verify browser version through Edge Settings > About Microsoft Edge
- Deploy browser update policies via enterprise management tools if applicable
- Monitor for user reports of suspicious UI behavior or unexpected authentication prompts
Evidence notes
CVE published 2026-05-18; modified 2026-05-19. Vendor advisory confirms affected versions and fix availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45494 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45494
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45494 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45494
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45494
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.