Microsoft Edge (Chromium-based) Spoofing Vulnerability

Date Jun 9, 2026
Type Patch Tuesday
Signal High-risk advisory
Vendor / Product Microsoft ยท Microsoft Edge (Chromium-based)
CVE CVE-2026-32208
High-risk advisory CVE-2026-32208

Summary

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. Published in June 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:N/A.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates. EPSS percentile: 20%.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-32208. Confirm whether Microsoft Edge (Chromium-based) is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.3%; percentile: 20%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.