Executive brief
Microsoft Edge is a widely used web browser for accessing internet and internal corporate resources. A vulnerability has been identified that could allow an attacker to execute malicious code on a user's computer if they are tricked into visiting a specially crafted website. This could lead to a total compromise of the user's workstation, including the theft of sensitive data, installation of malware, or unauthorized access to corporate applications.
Technical details
Microsoft Edge (Chromium-based) contains a remote code execution vulnerability likely stemming from improper input validation or memory corruption issues (CWE-20, CWE-94, CWE-119). The vulnerability is exploitable via the network vector without prior authentication, though it requires user interaction, such as a user navigating to a malicious URL. Successful exploitation allows an attacker to execute arbitrary code in the context of the browser process. Microsoft has released information regarding this vulnerability in their Security Update Guide, and users are advised to apply the latest browser updates to mitigate the risk.
Affected products
- Microsoft Edge (Chromium-based)
Timeline
- 2026-05-18: disclosed: Vulnerability published by Microsoft and NVD.