Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-45494

Опубликовано: 15 мая 2026
Источник: msrc
CVSS3: 5.4
EPSS Низкий

Описание

Microsoft Edge (Chromium-based) Spoofing Vulnerability

FAQ

According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability?

The Edge browser's tab-splitting feature, which allows users to browse two tabs simultaneously, only displays the domain prefix in the address bars instead of the full URL. This behavior can lead to phishing vulnerabilities, as attackers could exploit it to make malicious websites appear legitimate by mimicking trusted domain names.

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

The user would have to open a web page that contained a malicious iframe.

What is the version information for this release?

Microsoft Edge VersionDate ReleasedBased on Chromium Version
148.0.3967.7005/15/2026148.0.7778.168

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation More Likely

EPSS

Процентиль: 23%
0.00302
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVSS3: 5.4
github
3 месяца назад

Microsoft Edge (Chromium-based) Spoofing Vulnerability

EPSS

Процентиль: 23%
0.00302
Низкий

5.4 Medium

CVSS3