Junglewise Threat Intelligence

CVE-2026-55945: Microsoft Edge race condition in shared resource synchronization

CVE-2026-55945 · Severity: medium · CVSS 4.2 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Edge web browser that could allow an attacker with existing access to a computer to view sensitive information. This issue is caused by a timing error when the browser handles shared internal resources. While difficult to exploit, it could lead to the unauthorized disclosure of local data or a minor breach of system integrity.

Technical details

A race condition (CWE-362) exists in Microsoft Edge (Chromium-based) due to improper synchronization when accessing shared resources. An attacker with local access and low privileges can exploit this timing flaw to disclose information across security boundaries (indicated by the Scope: Changed in the CVSS vector). The attack complexity is high, suggesting specific timing or environmental conditions are required for a successful exploit. Microsoft has addressed this in version 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) < 150.0.4078.48

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats