Junglewise Threat Intelligence

CVE-2026-58299: Microsoft Edge for Android TOCTOU race condition

CVE-2026-58299 · Severity: high · CVSS 7.5 · Published 2026-07-03

Technologies: Microsoft Edge, Microsoft Edge (Chromium-based) for Android. Vendors: Microsoft.

Executive brief

Microsoft Edge for Android is a mobile web browser used to access the internet and corporate web applications. A security flaw has been identified that could allow a remote attacker to execute malicious code on a user's device if they are tricked into visiting a specifically crafted website. This could lead to the theft of sensitive data, unauthorized access to accounts, or a complete compromise of the mobile device.

Technical details

A race condition vulnerability (CWE-367) exists in Microsoft Edge (Chromium-based) for Android. The flaw is a Time-of-Check Time-of-Use (TOCTOU) issue that occurs during the processing of web content. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious webpage or interact with specially crafted content. Successful exploitation requires the attacker to win a timing race, which if successful, allows for arbitrary code execution in the context of the browser. Microsoft has addressed this in version 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) for Android < 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats