Executive brief
Microsoft Edge, the primary web browser for Windows systems, is vulnerable to a security flaw that could allow an attacker to take control of a user's computer. By tricking a user into visiting a malicious website, an attacker could execute unauthorized commands or install software without the user's permission. This poses a significant risk to data privacy and system integrity for any organization using the browser.
Technical details
A heap-based buffer overflow (CWE-122) exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The vulnerability is triggered when the browser improperly handles memory during the processing of specially crafted web content. An unauthenticated attacker can exploit this by hosting a malicious website and inducing a user to visit it (User Interaction required). Successful exploitation allows for remote code execution (RCE) within the context of the browser process. Microsoft has released a security update to address this issue.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication by Microsoft and NVD.