CVE-2026-0391: Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Other sources
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 143.0.3650.66
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0391?
CVE-2026-0391 has a severity rating that indicates a potential for significant impact due to spoofing vulnerabilities.
How do I fix CVE-2026-0391?
To fix CVE-2026-0391, ensure that you update Microsoft Edge (Chromium-based) to the latest version that addresses this vulnerability.
What types of attacks can CVE-2026-0391 enable?
CVE-2026-0391 can enable unauthorized attackers to perform spoofing attacks over a network by misrepresenting critical user interface information.
Which versions of Microsoft Edge are affected by CVE-2026-0391?
CVE-2026-0391 affects Microsoft Edge (Chromium-based) prior to version 143.0.3650.66.
Is CVE-2026-0391 a risk for Android users?
Yes, CVE-2026-0391 poses a risk specifically to users of Microsoft Edge (Chromium-based) on Android devices.