Executive brief
Microsoft Edge, a widely used web browser, contains a security flaw that allows an attacker to bypass built-in security protections. If exploited, this could allow an unauthorized party to access or modify sensitive data that the browser is intended to protect. This poses a risk to user privacy and the integrity of web-based transactions and corporate data accessed through the browser.
Technical details
An improper authorization vulnerability (CWE-285) exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw allows a remote, unauthenticated attacker to bypass security feature protections over a network. While the attack complexity is rated as high, a successful exploit could lead to a scope change, granting the attacker high confidentiality and integrity impacts. Users are advised to update to version 150.0.4078.48 or later to mitigate this risk.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory