Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A vulnerability has been identified that could allow an attacker to execute malicious code on a user's computer if they are tricked into visiting a specially crafted website. This could lead to unauthorized access to data, installation of malware, or disruption of the user's workstation.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Edge (Chromium-based) prior to version 150.0.4078.48. The flaw occurs when the browser accesses a resource using an incompatible type, which can be leveraged by an unauthorized attacker to achieve remote code execution. The attack vector is network-based and requires user interaction, such as a user visiting a malicious website. While the attack complexity is rated as high, successful exploitation allows the attacker to execute code in the context of the browser process. Users are advised to update to version 150.0.4078.48 or later to mitigate this risk.
Affected products
- Microsoft Edge (Chromium-based) < 150.0.4078.48
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory