CVE-2026-70331: Microsoft Edge for iOS Spoofing Vulnerability
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft Edge for iOS Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.4078.50
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker can act over a network without prior privileges, but user interaction is required. The available data does not specify the exact interaction or delivery mechanism.
What is the likely impact if exploitation succeeds?
This is a spoofing vulnerability with low confidentiality and integrity impact and no availability impact under the provided CVSS vector. An attacker may be able to cause misleading or untrustworthy content or prompts to be presented to a user.
Which products should be reviewed for exposure?
Review deployments of Microsoft Edge for iOS and Microsoft Edge (Chromium-based). The provided data does not identify affected versions, fixed versions, or configuration conditions.