A smartphone displays Microsoft Edge up to date, surrounded by AI, security, and app update graphics.
Microsoft Edge for iOS versions earlier than 150.0.4078.50 are listed as affected by CVE-2026-70331, a spoofing vulnerability involving input used in large-language-model prompting. Users and administrators should update the iOS app and verify its installed version against that boundary. NIST’s National Vulnerability Database describes the issue as allowing an unauthorized attacker to perform spoofing over a network.

What the vulnerability record establishes​

The published description identifies “improper neutralization of input used for LLM prompting.” That places the reported weakness in how input intended for a language model is handled. The description does not identify the affected AI feature or explain exactly what an attacker could impersonate, so it does not support a more specific claim about forged browser addresses, generated network traffic, stolen credentials, or device takeover.

Tenable repeats the same vulnerability description and lists August 28, 2026, as the publication date, citing MITRE and NVD. This provides another accessible record, but not independent confirmation of an exploitation technique or attack campaign. The available corroboration is database reporting rather than independently reported testing.

There is also a platform-label ambiguity worth preserving. NVD lists both “Microsoft Edge (Chromium-based)” and “Microsoft Edge for iOS” in its affected-product table, with the same version boundary, while the vulnerability description specifically names iOS. That broader product label alone should not be treated as confirmation that Windows or Android installations have the same exposure.

The version boundary and update decision​

NVD lists the affected range as 1.0.0.0 up to, but not including, 150.0.4078.50. For the iOS product explicitly named in the description, 150.0.4078.50 is therefore the minimum version outside the recorded affected range.

Microsoft’s Mobile Stable Channel release notes identify 150.0.4078.50 as an Android and iOS release dated July 6, 2026. They also document later iOS releases, including 153.0.4234.32 on September 14. Users do not need to seek out the older boundary build specifically; a newer available stable release also clears that threshold.

The practical response is to update Microsoft Edge through the iOS App Store. For managed deployments, administrators should compare the installed Edge version reported by their mobile-management inventory with the affected range, rather than treating an update assignment as proof that installation has completed.

Microsoft notes that mobile stable updates roll out progressively and may take time to appear in app stores. The relevant completion check remains the installed version: an iOS device still running Edge below 150.0.4078.50 remains within the published affected range, even if an update has been requested.

Neither the brief vulnerability description nor the mobile release history establishes a feature-specific workaround. Updating the affected iOS app is the supported version-based response; there is insufficient detail to promise that disabling a particular AI feature would remove the exposure.