Junglewise Threat Intelligence

CVE-2026-57993: Microsoft Edge SSRF in Chromium-based browser

CVE-2026-57993 · Severity: high · CVSS 7.4 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a widely used web browser for accessing internet and internal corporate resources. A security flaw in the browser could allow an attacker to trick the application into making unauthorized requests to internal or external network locations. This could lead to the exposure of sensitive information or allow an attacker to bypass network security controls by spoofing legitimate traffic.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Edge (Chromium-based) prior to version 150.0.4078.48. The flaw, classified as CWE-918, allows a remote, unauthenticated attacker to induce the browser to send crafted requests to unintended destinations. While the attack requires some level of user interaction (UI:R), the 'Changed' scope (S:C) indicates the vulnerability can impact resources beyond the browser's immediate security perimeter. Successful exploitation can lead to high confidentiality impacts by allowing the attacker to probe internal networks or access metadata services that are otherwise restricted. Microsoft has released updates to address this issue.

Affected products

  • Microsoft Edge (Chromium-based) < 150.0.4078.48

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats