Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that could allow an unauthorized person to bypass built-in security protections over the network. This could potentially lead to unauthorized access to data or disruption of the browser's normal operations.
Technical details
A type confusion vulnerability (CWE-843) exists in Microsoft Edge (Chromium-based) when accessing resources using an incompatible type. This flaw allows a remote, unauthenticated attacker to bypass security features via the network without any user interaction. According to the CVSS metrics, the vulnerability has a scope change, meaning it could impact components beyond the browser itself, potentially affecting confidentiality, integrity, and availability. Microsoft has addressed this in versions 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: disclosed: Initial publication of the CVE record.
- 2026-07-03: advisory: Microsoft released the security advisory and update guide.