Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw in how the browser processes certain types of data could allow a remote attacker to take control of a user's computer if they are tricked into visiting a malicious website. This could lead to the theft of sensitive information, installation of malware, or disruption of business operations.
Technical details
A remote code execution vulnerability exists in Microsoft Edge (Chromium-based) categorized as CWE-502 (Deserialization of Untrusted Data). The flaw occurs when the browser improperly processes serialized data from an external source, allowing an attacker to execute arbitrary code in the context of the browser process. Exploitation requires a user to visit a specially crafted website (User Interaction required) and is considered high complexity due to specific environmental or timing requirements. Microsoft has addressed this issue in version 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) < 150.0.4078.48
Timeline
- 2026-07-11: disclosed
- 2026-07-11: advisory