Junglewise Threat Intelligence

CVE-2026-57974: Microsoft Edge integer overflow remote code execution

CVE-2026-57974 · Severity: high · CVSS 8.8 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to run malicious code on a user's computer. This typically occurs if a user is tricked into visiting a specially crafted website. If successful, an attacker could gain control over the system, potentially leading to data theft or further malware installation.

Technical details

This vulnerability is classified as an integer overflow or wraparound (CWE-190) within the Chromium-based engine of Microsoft Edge. The flaw is exploitable over the network and requires minimal user interaction, such as a user visiting a malicious webpage. An attacker can leverage this memory corruption issue to achieve remote code execution (RCE) in the context of the browser process. The vulnerability affects versions prior to 150.0.4078.48, and Microsoft has released updates to address the issue.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial publication of CVE-2026-57974 by Microsoft and NVD.

References

Related threats