Executive brief
A security vulnerability in Microsoft Edge could allow an attacker to access files or directories on a user's computer that should remain private. This occurs when a user visits a malicious website, potentially leading to the theft of sensitive personal or corporate data. While the attack requires the user to take an action like clicking a link, it poses a significant risk to data confidentiality.
Technical details
Microsoft Edge (Chromium-based) is vulnerable to an information disclosure flaw categorized as CWE-552 (Files or Directories Accessible to External Parties). The vulnerability allows a remote, unauthenticated attacker to access sensitive files or directory structures over the network, provided they can induce a user to interact with a malicious webpage (User Interaction: Required). The CVSS vector indicates a Scope change (S:C), suggesting the impact may extend beyond the browser's sandbox to the underlying file system. Microsoft has released security updates to address this issue; users should ensure they are running the latest patched version of the browser.
Affected products
- Microsoft Edge (Chromium-based) All versions prior to the July 2026 security update
Timeline
- 2026-07-26: disclosed: Initial disclosure by Microsoft and NVD
- 2026-07-26: advisory: MSRC advisory published