Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2025-62224: Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N) and integrity (I:N), but could lead to some loss of availability (A:L). What does that mean for this vulnerability?

An attacker using either a specially-crafted page or a content script injected into a target page can show an extension’s popup over a permission prompt or screen share dialog allowing the extension to spoof parts of the prompt’s UI that shows its origin.

Microsoft Security Response Center
#vulnerability#android#microsoft#chrome#Microsoft Edge for Android#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2026-0628: Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag