Executive brief
Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to execute malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into visiting a specially crafted website. If successful, this could lead to a full compromise of the user's system, unauthorized data access, or service disruption.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Edge (Chromium-based) due to the improper handling of resources using incompatible types. The vulnerability is reachable over the network and requires no prior authentication, though it does require user interaction (such as visiting a malicious site) and involves high attack complexity. Successful exploitation allows for remote code execution (RCE) with the privileges of the browser process. Microsoft has addressed this in version 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial advisory published by Microsoft and NVD.