Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that could allow a remote attacker to execute malicious code on a user's computer if they are tricked into visiting a specially crafted website. This could lead to a full system compromise, unauthorized data access, or the installation of malware.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Edge (Chromium-based) prior to version 150.0.4078.48. The flaw occurs when the browser accesses a resource using an incompatible type, which can be leveraged by an attacker to achieve remote code execution (RCE). Exploitation requires a remote attacker to entice a user to visit a malicious webpage (User Interaction required) and typically involves high complexity due to modern browser mitigations. If successful, the attacker can execute code in the context of the browser process, potentially escaping the sandbox to compromise the underlying system. Users are advised to update to version 150.0.4078.48 or later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.47
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory