Junglewise Threat Intelligence

CVE-2026-58295: Microsoft Edge type confusion security bypass

CVE-2026-58295 · Severity: high · CVSS 8.3 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that could allow an unauthorized person to bypass built-in security protections over the network. This could potentially lead to unauthorized access to data or disruption of the browser's normal operations.

Technical details

A type confusion vulnerability (CWE-843) exists in Microsoft Edge (Chromium-based) when accessing resources using an incompatible type. This flaw allows a remote, unauthenticated attacker to bypass security features via the network without any user interaction. According to the CVSS metrics, the vulnerability has a scope change, meaning it could impact components beyond the browser itself, potentially affecting confidentiality, integrity, and availability. Microsoft has addressed this in versions 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: disclosed: Initial publication of the CVE record.
  • 2026-07-03: advisory: Microsoft released the security advisory and update guide.

References

Related threats