Cross-site scripting in Microsoft Edge - CVE-2026-77490
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing.
The vulnerability exists due to improper neutralization of input during web page generation in Microsoft Edge (Chromium-based) when rendering web pages. A remote attacker can host a specially crafted website to perform spoofing.
User interaction is required: a user must access the malicious website and click a popup while multiple affected browser instances are open.