Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw in how the browser handles file links could allow an attacker to trick a user into revealing sensitive information. If successfully exploited, this could lead to the unauthorized disclosure of data over the network, potentially compromising user privacy or corporate secrets.
Technical details
A vulnerability classified as CWE-59 (Improper Link Resolution Before File Access) exists in Microsoft Edge (Chromium-based). The flaw occurs when the browser fails to properly validate or resolve symbolic links or shortcuts before accessing the underlying file. An unauthenticated remote attacker can exploit this by enticing a user to interact with a malicious link or site (User Interaction required). Successful exploitation allows the attacker to bypass security boundaries and disclose sensitive information from the victim's system over the network. Microsoft has addressed this in versions 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) < 150.0.4078.48
Timeline
- 2026-07-03: advisory: Microsoft published the advisory and NVD record.