CVE-2026-35429
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-35429 is a UI misrepresentation (spoofing) vulnerability in Microsoft Edge for Android that allows an unauthenticated network attacker to deceive users about the authenticity of websites or content they are viewing. The flaw is classified under CWE-451 (User Interface Misrepresentation of Critical Information) and affects Microsoft Edge for Android versions prior to 148.0.3967.55. It was published on May 12, 2026, with patches made available the same day via Microsoft MSRC and GitHub Advisories. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (MSRC, GitHub Advisory).

Technical details

The root cause is CWE-451 — the browser's user interface fails to properly represent critical information (such as the origin or URL of a page) to the user, enabling an attacker to obscure or spoof that information. This type of flaw is commonly leveraged in phishing attacks, where a malicious site or crafted network interaction causes the browser to display misleading UI elements (e.g., a spoofed address bar or security indicator). Exploitation requires user interaction — a victim must visit or interact with attacker-controlled content — but no privileges or authentication are required on the attacker's side. No public proof-of-concept code has been identified (GitHub Advisory, MSRC).

Impact

Successful exploitation allows an attacker to misrepresent critical UI information in Microsoft Edge for Android, tricking users into believing they are interacting with a legitimate website or trusted content when they are not. The primary impact is a low confidentiality loss — users may be deceived into submitting sensitive information (credentials, personal data) to attacker-controlled sites. There is no direct integrity or availability impact, and the scope is unchanged, meaning the vulnerability does not enable lateral movement or system-level compromise beyond the spoofing deception itself (MSRC, GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. The EPSS score is approximately 0.056–0.064%, placing it in the 20th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, MSRC).

Mitigation and workarounds

Microsoft has released a patch addressing this vulnerability in Microsoft Edge for Android version 148.0.3967.55 and later. Users and administrators should update the Edge app on Android devices to this version or newer via the Google Play Store. As an interim measure, users should be advised to verify website authenticity carefully, avoid entering sensitive information on unfamiliar sites, and be alert to any suspicious UI behavior or URL mismatches in the browser (MSRC, GitHub Advisory).

Community reactions

The vulnerability was noted in standard Patch Tuesday coverage for May 2026, with mentions in security community outlets and aggregators. Coverage was routine given the medium severity rating and lack of active exploitation. No significant researcher commentary or notable social media discussion beyond standard vulnerability tracking has been identified (Petri).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management