CVE-2026-0391Disclosure(microsoft / edge_chromium)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch microsoft edge_chromium systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-451

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edge_chromium

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-02-06)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
edge_chromium

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-05: 1Mentions · 2026-02-06: 3Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 102-0502-06
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-051
General1
2026-02-063
Disclosure2Patch1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Microsoft Edge (CVE-2026-0391) https://vuldb.com/?id.344602

    Post summary

    A new CVE for Microsoft Edge with increased severity has been disclosed, but no additional details such as exploit code, patch, or active exploitation are provided.

    01001114
    2.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-0391 User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-0391

    Post summary

    The CVE details a UI misrepresentation in Microsoft Edge for Android that could allow spoofing, but no PoC, exploit, or patch information is provided.

    00010238
    56.5K followersView on X
  • WinBuzzer@WBuzzer
    Disclosure

    https://winbuzzer.com/2026/02/06/cve-2026-0391-microsoft-edge-android-ui-spoofing-xcxwbn/ CVE-2026-0391: Edge Android Flaw Enables Spoofing Attacks #MicrosoftEdge #Security #Cybersecurity #Microsoft #Android #WebBrowsers #Phishing #CredentialTheft #ZeroDayVulnerabilities #Chromium https://t.co/cST9OpGekZ

    Post summary

    The article announces CVE‑2026‑0391, a Microsoft Edge Android UI spoofing flaw that could enable spoofing attacks, but it provides no proof‑of‑concept, exploit code, active exploitation evidence, or patch details.

    00000128
    37.4K followersView on X
  • kawn@kawn2020
    Patch

    #microsoftupdate #securityupdate #Edge マイクロソフトが Microsoft Edge Stable Channel (Version 144.0.3719.115) をリリース. CVE ベースで脆弱性 1 件に対処. ・CVE-2026-0391 https://x.com/kawn2020/status/2019593956418535454

    Post summary

    Microsoft released Edge Stable Channel update 144.0.3719.115 to patch CVE-2026-0391, with no PoC or exploit details disclosed.

    00000109
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftedge_chromium-android-

Explore more