Junglewise Threat Intelligence

CVE-2026-57977: Microsoft Edge Chromium-based cross-site scripting

CVE-2026-57977 · Severity: high · CVSS 7.1 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a widely used web browser for accessing internet and internal corporate resources. A security vulnerability has been identified that allows an attacker to perform spoofing and cross-site scripting (XSS) attacks. If exploited, this could allow an attacker to trick users into interacting with malicious content or potentially compromise user sessions and data within the browser.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Edge (Chromium-based) due to improper neutralization of input during web page generation. The vulnerability (CWE-79) allows a remote, unauthenticated attacker to perform spoofing attacks over the network. Exploitation requires user interaction, typically involving a user visiting a specially crafted website. Successful exploitation could allow the attacker to execute arbitrary script in the context of the user's browser session, leading to a loss of integrity and limited confidentiality. Microsoft has addressed this in version 150.0.4078.48.

Affected products

  • Microsoft Edge (Chromium-based) < 150.0.4078.48

Timeline

  • 2026-07-03: advisory: NVD and Microsoft published the advisory.

References

Related threats