CVE-2026-33118: Microsoft Edge (Chromium-based) Spoofing Vulnerability

Overview

Severity
Medium (CVSS 4.3)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
Category
Edge - Chromium
Exploit Status
Not Exploited
Patch Tuesday
2026-Apr
Released
2026-04-10
EPSS Score
0.06% (percentile: 19.8%)

FAQ

According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L),but lead to no loss of availability (A:N) and integrity (I:N)? What does that mean for this vulnerability? An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality) but not all resources within the impacted component may be divulged to the attacker. The attacker cannot make changes to disclosed information (Integrity) or limit access to the resource (Availability). According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker would have to send the victim a malicious file that the victim would have to execute. What is the version information for this release? Microsoft Edge Version Date Released Based on Chromium Version 147.0.3912.60 04/10/2026 147.0.7727.55/.56

Affected Products (1)

Browser

  • Microsoft Edge (Chromium-based)

Acknowledgments

nakanoou

Revision History

  • 2026-04-10: Information published.