Junglewise Threat Intelligence

CVE-2026-42838: Microsoft Edge Chromium injection privilege escalation

CVE-2026-42838 · Severity: medium · CVSS 5.4 · Published 2026-05-12

Technologies: Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used to access internet and internal network resources. A vulnerability in how the browser handles certain data allows a remote attacker to potentially gain higher-level permissions on a user's system. This could lead to unauthorized access to sensitive information or the ability to perform actions on behalf of the user if they visit a malicious website.

Technical details

An injection vulnerability exists in Microsoft Edge (Chromium-based) due to improper neutralization of special elements in output used by a downstream component (CWE-74). The flaw allows an unauthenticated attacker to achieve privilege escalation over a network. Exploitation requires user interaction, typically involving a user visiting a specially crafted website. According to the CVSS vector, the attack has low complexity and results in low impacts to confidentiality and integrity, with no impact on availability. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Edge (Chromium-based)

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats