Executive brief
Microsoft Edge, a widely used web browser, contains a security flaw that could allow an attacker to execute malicious code on a user's computer. This typically occurs if a user is tricked into visiting a specially crafted website or clicking a malicious link. Successful exploitation could lead to unauthorized software installation, data theft, or a compromise of the user's system.
Technical details
A remote code execution vulnerability exists in Microsoft Edge (Chromium-based) due to improper input validation (CWE-20). The vulnerability is reachable over the network and does not require administrative privileges, though it does require user interaction, such as visiting a malicious webpage. An attacker who successfully exploits this vulnerability could execute arbitrary code in the context of the browser process. Microsoft has addressed this issue in version 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication by Microsoft and NVD.