CVE-2026-58278: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.4078.48
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58278?
The severity of CVE-2026-58278 is categorized as medium with a score of 5.4.
What kind of vulnerability is CVE-2026-58278?
CVE-2026-58278 is a spoofing vulnerability due to a server-side request forgery in Microsoft Edge (Chromium-based).
How does CVE-2026-58278 impact users?
CVE-2026-58278 allows an unauthorized attacker to perform spoofing over a network, potentially compromising user trust.
How do I fix CVE-2026-58278?
To address CVE-2026-58278, users should update Microsoft Edge to the latest version provided by Microsoft.
What software is affected by CVE-2026-58278?
CVE-2026-58278 affects Microsoft Edge and Microsoft Edge Chromium-based browsers.