Executive brief
A security bypass vulnerability exists in Microsoft Edge, the primary web browser for Windows systems. An attacker could exploit this flaw to circumvent built-in security protections, potentially leading to unauthorized access to limited information or the ability to perform restricted actions. Successful exploitation requires a user to interact with a malicious website or link.
Technical details
A security feature bypass vulnerability exists in Microsoft Edge (Chromium-based) due to improper input validation (CWE-20). An unauthenticated attacker can exploit this over the network by inducing a user to visit a specially crafted website or click a malicious link. The vulnerability allows the attacker to bypass browser-level security controls, though the impact is limited to low confidentiality and integrity losses. Microsoft has addressed this issue in their security update guide, and users are advised to update to the latest version of the Edge browser.
Affected products
- Microsoft Edge (Chromium-based)
Timeline
- 2026-05-18: disclosed
- 2026-05-18: advisory