Executive brief
Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to access sensitive information. An attacker would need to trick a user into visiting a malicious website or performing a specific action to trigger the vulnerability. If successful, this could lead to the unauthorized disclosure of private data handled by the browser.
Technical details
This vulnerability is classified as a 'Use-After-Free' or 'Operation on a Resource after Expiration or Release' (CWE-672) within the Chromium-based Microsoft Edge browser. An unauthenticated attacker can exploit this over the network, though the attack requires high complexity and user interaction, such as convincing a victim to visit a specially crafted webpage. Successful exploitation allows the attacker to bypass security boundaries and disclose sensitive information from the browser's memory. Microsoft has addressed this in version 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial disclosure by Microsoft and NVD