You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-35429
About this tag
CVE-2026-35429 is a security vulnerability affecting Microsoft Edge for Android that enables UI spoofing attacks. An attacker can exploit this flaw over the network by hosting a malicious website and persuading a user to open it, causing the browser interface to misrepresent critical information. This spoofing can be leveraged for phishing without requiring authentication or local access. While not a remote code execution or wormable bug, it is a browser trust vulnerability that can be abused in modern phishing campaigns. Discussions on WindowsForum cover the patch version, risk assessment, and practical implications for Android users.
An attacker could exploit CVE-2026-35429 over the network by hosting a maliciously crafted website and persuading a Microsoft Edge for Android user to open it, where the browser’s interface could misrepresent critical information and enable spoofing without requiring authentication or local...