You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-45494
About this tag
CVE-2026-45494 is a medium-severity spoofing vulnerability in Microsoft Edge, disclosed in May 2026. It affects Chromium-based Edge versions before 148.0.3967.70. The vulnerability allows a crafted browsing experience to mislead users about a page's true identity, specifically through a split-tab address bar spoofing technique. This can trick users into trusting the wrong site, potentially exposing credentials or leading to actions under false assumptions. Unlike remote code execution or system takeover, this bug focuses on user deception, making it relevant to real-world browser attacks. Discussions on WindowsForum cover the technical details, practical impact, and mitigation steps for CVE-2026-45494.
Microsoft disclosed CVE-2026-45494 in May 2026 as a medium-severity spoofing vulnerability in Microsoft Edge, affecting Chromium-based Edge versions before 148.0.3967.70 and allowing a crafted browsing experience to mislead users about a page’s true identity. The practical impact is not remote...