Junglewise Threat Intelligence

CVE-2026-58283: Microsoft Edge type confusion in Chromium engine

CVE-2026-58283 · Severity: high · CVSS 8.1 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to impersonate legitimate websites or services. By exploiting this vulnerability, a remote attacker could deceive users into providing sensitive information or interacting with malicious content. This poses a risk to data integrity and could lead to unauthorized access to user accounts or corporate resources.

Technical details

A type confusion vulnerability (CWE-843) exists in Microsoft Edge (Chromium-based) when processing resources using incompatible types. The flaw allows an unauthenticated attacker to conduct spoofing attacks over the network. While the attack complexity is rated as high, successful exploitation could lead to a scope change, impacting the integrity of the browser's security boundaries. The vulnerability is addressed in versions starting from 150.0.4078.48.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats