Executive brief
Microsoft Edge, a widely used web browser, contains a security flaw that could allow an attacker to run unauthorized code on a user's computer. This typically occurs if a user is tricked into visiting a malicious website or clicking a compromised link. If exploited, an attacker could potentially gain control over the browser session, access sensitive information, or disrupt the user's operations.
Technical details
A vulnerability exists in Microsoft Edge (Chromium-based) due to improper input validation (CWE-20). An unauthenticated attacker can exploit this flaw by hosting a specially crafted website and convincing a user to visit it. The attack vector is network-based, but it requires user interaction and has a high attack complexity. Successful exploitation allows for remote code execution within the context of the browser, potentially leading to a sandbox escape or compromise of the host system. Microsoft has released updates to address this issue in versions 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory