Executive brief
Microsoft Edge, a widely used web browser, contains a security flaw that could allow an attacker to take control of a user's computer. By tricking a user into visiting a malicious website, an attacker could execute unauthorized commands or install software. This could lead to the theft of sensitive personal data or a complete compromise of the affected device.
Technical details
A use-after-free (CWE-416) vulnerability exists in Microsoft Edge (Chromium-based) prior to version 150.0.4078.48. The flaw occurs when the browser continues to use a memory pointer after it has been freed, leading to memory corruption. An unauthenticated remote attacker can exploit this by hosting a specially crafted website and inducing a user to visit it. Successful exploitation allows for remote code execution (RCE) within the context of the browser, potentially escaping the sandbox to compromise the underlying host. Microsoft has released updates to address this issue.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial publication of CVE-2026-58288 by Microsoft and NVD.
- 2026-07-03: patched: Fixed in version 150.0.4078.48.