Executive brief
Microsoft Edge is a web browser used to access internet and intranet resources. A security flaw allows an attacker to bypass authentication mechanisms, potentially leading to unauthorized data modification or tampering. This could result in a loss of data integrity or the presentation of fraudulent information to the user.
Technical details
This vulnerability is classified as an authentication bypass using an alternate path or channel (CWE-288) within the Chromium-based version of Microsoft Edge. An unauthenticated attacker can exploit this over the network, though user interaction is required for a successful attack. The flaw allows for tampering and unauthorized access to certain data (Low Confidentiality and Low Integrity impact). Microsoft has addressed this in versions 150.0.4078.80 and later.
Affected products
- Microsoft Edge (Chromium-based) < 150.0.4078.80
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory