CVE-2026-58595
HIGHCVSS 8.1/10EPSS 0.47%
Last modified
CVE-2026-58595 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Bing Search | < 33.4.440529002 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-58595?
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.
How severe is CVE-2026-58595?
CVE-2026-58595 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.47% probability of exploitation in the next 30 days.
How do I fix CVE-2026-58595?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5859Integer overflow in WebML in Google Chrome prior to 147.0.77…8.8
- CVE-2026-58590Missing Authorization vulnerability in Drupal FlowDrop allow…5.4
- CVE-2026-58591Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2026-58592Ladybird contains a dangling-reference memory-safety flaw in…8.9
- CVE-2026-58593NodeBB does not bind the claimed author of an inbound Activi…8.7
- CVE-2026-58594Integer overflow or wraparound in Windows RDP allows an unau…9.8
- CVE-2026-58596Untrusted pointer dereference in Microsoft Edge (Chromium-ba…8.3
- CVE-2026-58597Insufficient ui warning of dangerous operations in Microsoft…4.3
- CVE-2026-58598Concurrent execution using shared resource with improper syn…7
- CVE-2026-5860Use after free in WebRTC in Google Chrome prior to 147.0.772…8.8
- CVE-2026-58601Heap-based buffer overflow in Virtual Hard Disk (VHD) Minipo…7.8
- CVE-2026-58602Use after free in Windows Kernel Mode Driver allows an autho…7.8
Are you affected by CVE-2026-58595?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
