Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw in the browser's access controls could allow a remote attacker to bypass built-in security protections. If exploited, this could lead to the unauthorized disclosure of sensitive user information or allow an attacker to perform actions on behalf of the user.
Technical details
An improper access control vulnerability (CWE-284) exists in Microsoft Edge (Chromium-based). The flaw allows a remote, unauthenticated attacker to bypass security features via a network-based attack vector. Exploitation requires user interaction, such as visiting a malicious website. Successful exploitation can lead to a scope change (CVSS S:C), potentially allowing the attacker to access sensitive data or impact the integrity of the browser session. Microsoft has addressed this in version 150.0.4078.50 and later.
Affected products
- Microsoft Edge (Chromium-based) < 150.0.4078.50
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory