Junglewise Threat Intelligence

CVE-2026-57987: Microsoft Edge SSRF in Chromium-based browser

CVE-2026-57987 · Severity: medium · CVSS 6.5 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to trick the browser into making unauthorized requests to internal or external network resources. If successfully exploited, an attacker could potentially access sensitive information or spoof network communications by convincing a user to visit a malicious website. This could lead to the exposure of internal data that is not intended to be accessible from the public internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw, classified as CWE-918, allows a remote, unauthenticated attacker to induce the browser to initiate requests to unintended locations. Exploitation requires user interaction, typically involving a victim visiting a specially crafted URL. A successful attack could result in the disclosure of sensitive information from internal network services or the ability to perform network spoofing. Microsoft has addressed this issue in the latest browser updates.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Microsoft published the security advisory and NVD entry.

References

Related threats