Executive brief
Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to execute unauthorized code on a user's system. By tricking a user into visiting a malicious website or clicking a specific link, an attacker could potentially modify files or disrupt the browser's operation. This poses a risk to organizational security as it could be used as an entry point for further malicious activity on an employee's workstation.
Technical details
A relative path traversal vulnerability (CWE-23) exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw allows an unauthenticated attacker to achieve remote code execution by exploiting improper handling of file paths over a network. While the attack vector is network-based, it requires user interaction, such as a user visiting a specially crafted website. Successful exploitation allows the attacker to compromise system integrity and impact availability, though the CVSS score suggests confidentiality is not directly impacted by this specific bug. Microsoft has released updates to address this vulnerability.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication by Microsoft and NVD