CVE-2026-0391
vulnerability analysis and mitigation

Overview

CVE-2026-0391 is a UI misrepresentation (spoofing) vulnerability in Microsoft Edge (Chromium-based) for Android, classified under CWE-451 (User Interface Misrepresentation of Critical Information). It allows an unauthorized remote attacker to perform spoofing attacks over a network by manipulating how critical information is displayed in the browser's user interface. The vulnerability affects Microsoft Edge (Chromium-based) for Android versions prior to 143.0.3650.66. It was published on December 4, 2025, with security updates released on February 10, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (MSRC Advisory).

Technical details

The root cause is CWE-451 — User Interface Misrepresentation of Critical Information — where the Android version of Microsoft Edge fails to accurately display security-critical information (such as URLs or origin indicators) to the user. This allows an attacker to craft a scenario where the browser's UI misleads the user into believing they are interacting with a trusted or legitimate source when they are not. The attack vector is network-based, requires no privileges and no user interaction, but does require high attack complexity, suggesting the attacker must engineer specific conditions (e.g., a man-in-the-middle position or a specially crafted web page) to trigger the misrepresentation (MSRC Advisory). No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation of this vulnerability enables an attacker to deceive users into believing they are interacting with legitimate content, websites, or security indicators within Microsoft Edge on Android. The primary risk is phishing — attackers could leverage the spoofed UI to steal credentials, session tokens, or other sensitive information, or to distribute malware by masquerading as trusted sites. Confidentiality impact is rated High (sensitive data exposure), integrity impact is Low (limited manipulation), and there is no availability impact (MSRC Advisory, BleepingComputer).

Exploitation steps

  1. Reconnaissance: Identify Android users running Microsoft Edge (Chromium-based) versions prior to 143.0.3650.66, potentially through targeted phishing campaigns or by monitoring mobile traffic.
  2. Setup malicious infrastructure: Prepare a malicious web server or network position (e.g., rogue Wi-Fi access point or man-in-the-middle proxy) capable of serving crafted content that triggers the UI misrepresentation flaw.
  3. Trigger UI spoofing: Deliver a specially crafted web page or network response that exploits the CWE-451 flaw, causing Edge for Android to display misleading security indicators — such as a falsified URL bar, origin display, or security badge — making malicious content appear to originate from a trusted source.
  4. Social engineering / credential harvesting: With the spoofed UI in place, prompt the victim to enter credentials, approve permissions, or download content under the false impression they are interacting with a legitimate site.
  5. Exfiltrate data: Collect submitted credentials or sensitive information from the attacker-controlled backend (MSRC Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous HTTPS traffic from Android devices running Edge to unknown or newly registered domains; traffic routed through suspicious proxy or man-in-the-middle infrastructure.
  • Logs: Mobile device management (MDM) logs showing Edge for Android version below 143.0.3650.66 still in use after the February 10, 2026 patch release.
  • User Reports: End-user reports of unexpected login prompts, certificate warnings being bypassed, or unfamiliar sites appearing to have trusted indicators in Edge on Android.
  • Network: DNS queries from mobile devices to lookalike or typosquatted domains that could be used in conjunction with UI spoofing attacks.

Mitigation and workarounds

Microsoft released a patch addressing this vulnerability on February 10, 2026; users should update Microsoft Edge (Chromium-based) for Android to version 143.0.3650.66 or later (MSRC Advisory). Organizations should deploy Mobile Device Management (MDM) policies to enforce automatic updates for Microsoft Edge on Android devices. As an interim measure, users unable to patch immediately should be educated to carefully verify URLs and security indicators before entering sensitive information, and should avoid connecting to untrusted Wi-Fi networks that could facilitate man-in-the-middle attacks.

Community reactions

CVE-2026-0391 was covered as part of broader Microsoft February 2026 Patch Tuesday reporting, which addressed 58–59 vulnerabilities including six actively exploited zero-days (BleepingComputer, The Hacker News). Sophos and SANS ISC also published Patch Tuesday reviews covering the February 2026 update cycle (Sophos Blog, SANS ISC). Community discussion on Reddit noted the Edge Android spoofing flaw, though it attracted limited attention compared to the zero-day vulnerabilities patched in the same cycle (Reddit). No significant independent researcher commentary or dedicated technical write-ups specific to this CVE have been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management