Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that allows an unauthorized attacker to remotely execute malicious code on a user's computer. If exploited, this could lead to a total compromise of the device, allowing attackers to steal sensitive data, install malware, or disrupt business operations.
Technical details
This vulnerability is classified as CWE-73 (External Control of File Name or Path) within the Chromium-based version of Microsoft Edge. The flaw allows an unauthenticated attacker to manipulate file paths or names, leading to remote code execution (RCE) over the network. While the attack vector is network-based and requires no prior privileges or user interaction, the attack complexity is rated as high, suggesting specific environmental conditions or timing may be required for successful exploitation. Microsoft has addressed this in version 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory