CVE-2026-45489
edge_chromium: Exposed Dangerous Method or Function (CVE-2026-45489)
mediumEPSS 0.9%
Affected
- microsoft/edge_chromium
lt *..150.0.4078.48
Description
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
microsoftedge_chromium
150.0.4078.48fixed from 150.0.4078.48Metrics
Show all metrics
Severity
medium
80.56
no public PoC known
6.5
Published
2026-07-03 20:35 UTC
CWE-749
Weakness classes (CWE)
CWE-749Base
Exposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-07-03 21:17 UTC· secure@microsoft.com
- Affected: Microsoft Edge (Chromium-based)
- Description: Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45489