Executive brief
Microsoft Edge, a widely used web browser, contains a security flaw that could allow an attacker to execute malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into visiting a specially crafted website or clicking a malicious link. If successful, the attacker could gain full control over the user's system, potentially leading to data theft or further network compromise.
Technical details
An improper authorization vulnerability (CWE-285) exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw allows a remote, unauthenticated attacker to achieve arbitrary code execution via a network-based attack vector. Exploitation requires user interaction, such as visiting a malicious webpage, and is characterized by high complexity due to the specific conditions needed to bypass authorization checks. Successful exploitation results in a full compromise of confidentiality, integrity, and availability (CVSS 8.3). Microsoft has released updates to address this issue.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial disclosure by Microsoft and NVD publication.