Spoofing attack in Microsoft Edge - CVE-2026-45494
Published: May 18, 2026
Microsoft Edge
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the Edge browser's tab-splitting feature, which allows users to browse two tabs simultaneously, only displays the domain prefix in the address bars instead of the full URL. A remote attacker can trick the victim into opening a web page with a malicious iframe and perform spoofing attack.