Executive brief
Microsoft Edge, the primary web browser for Windows systems, is affected by a critical security vulnerability. An attacker could exploit this flaw to remotely execute malicious code on a user's computer through the network. This could lead to a complete compromise of the system, allowing unauthorized access to sensitive data and disruption of business operations.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Edge (Chromium-based) prior to version 150.0.4078.48. The flaw occurs when the browser accesses a resource using an incompatible type, which can be leveraged by a remote, unauthenticated attacker to execute arbitrary code. While the attack vector is network-based, the CVSS score reflects a high attack complexity, suggesting specific conditions or configurations may be required for successful exploitation. The vulnerability has a high impact on confidentiality, integrity, and availability, and it allows for scope traversal. Users are advised to update to version 150.0.4078.48 or later to mitigate this risk.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.47
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory