PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45494 Microsoft CVE debrief

A spoofing vulnerability in Microsoft Edge (Chromium-based) allows an attacker to manipulate UI elements to deceive users. The vulnerability has a CVSS 3.1 score of 5.4 (Medium severity) and is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). Affected versions are prior to 148.0.3967.70. Microsoft has released a security update addressing this issue.

Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-18
Original CVE updated
2026-05-19
Advisory published
2026-05-18
Advisory updated
2026-05-19

Who should care

End users and enterprise administrators running Microsoft Edge (Chromium-based) versions prior to 148.0.3967.70. Organizations with managed browser deployments should prioritize this update to prevent potential phishing or credential harvesting attacks leveraging spoofed UI elements.

Technical summary

This vulnerability in Microsoft Edge (Chromium-based) enables UI spoofing attacks where malicious content could be rendered to appear as legitimate browser interface elements. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N) indicates network attack vector, low attack complexity, no privileges required, but requires user interaction. The confidentiality and integrity impacts are low, with no availability impact. The underlying weakness is CWE-79, typically associated with cross-site scripting contexts where input sanitization failures allow injection of malicious content.

Defensive priority

medium

Recommended defensive actions

  • Update Microsoft Edge to version 148.0.3967.70 or later
  • Verify browser version through Edge Settings > About Microsoft Edge
  • Deploy browser update policies via enterprise management tools if applicable
  • Monitor for user reports of suspicious UI behavior or unexpected authentication prompts

Evidence notes

CVE published 2026-05-18; modified 2026-05-19. Vendor advisory confirms affected versions and fix availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45494 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45494

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45494 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45494

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.