
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0391 is a UI misrepresentation (spoofing) vulnerability in Microsoft Edge (Chromium-based) for Android, classified under CWE-451 (User Interface Misrepresentation of Critical Information). It allows an unauthorized remote attacker to perform spoofing attacks over a network by manipulating how critical information is displayed in the browser's user interface. The vulnerability affects Microsoft Edge (Chromium-based) for Android versions prior to 143.0.3650.66. It was published on December 4, 2025, with security updates released on February 10, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (MSRC Advisory).
The root cause is CWE-451 — User Interface Misrepresentation of Critical Information — where the Android version of Microsoft Edge fails to accurately display security-critical information (such as URLs or origin indicators) to the user. This allows an attacker to craft a scenario where the browser's UI misleads the user into believing they are interacting with a trusted or legitimate source when they are not. The attack vector is network-based, requires no privileges and no user interaction, but does require high attack complexity, suggesting the attacker must engineer specific conditions (e.g., a man-in-the-middle position or a specially crafted web page) to trigger the misrepresentation (MSRC Advisory). No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation of this vulnerability enables an attacker to deceive users into believing they are interacting with legitimate content, websites, or security indicators within Microsoft Edge on Android. The primary risk is phishing — attackers could leverage the spoofed UI to steal credentials, session tokens, or other sensitive information, or to distribute malware by masquerading as trusted sites. Confidentiality impact is rated High (sensitive data exposure), integrity impact is Low (limited manipulation), and there is no availability impact (MSRC Advisory, BleepingComputer).
Microsoft released a patch addressing this vulnerability on February 10, 2026; users should update Microsoft Edge (Chromium-based) for Android to version 143.0.3650.66 or later (MSRC Advisory). Organizations should deploy Mobile Device Management (MDM) policies to enforce automatic updates for Microsoft Edge on Android devices. As an interim measure, users unable to patch immediately should be educated to carefully verify URLs and security indicators before entering sensitive information, and should avoid connecting to untrusted Wi-Fi networks that could facilitate man-in-the-middle attacks.
CVE-2026-0391 was covered as part of broader Microsoft February 2026 Patch Tuesday reporting, which addressed 58–59 vulnerabilities including six actively exploited zero-days (BleepingComputer, The Hacker News). Sophos and SANS ISC also published Patch Tuesday reviews covering the February 2026 update cycle (Sophos Blog, SANS ISC). Community discussion on Reddit noted the Edge Android spoofing flaw, though it attracted limited attention compared to the zero-day vulnerabilities patched in the same cycle (Reddit). No significant independent researcher commentary or dedicated technical write-ups specific to this CVE have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."