Executive brief
Microsoft Edge, a widely used web browser, is affected by a security flaw that could allow an attacker to gain elevated permissions on a user's system. By tricking a user into visiting a malicious website or clicking a specific link, an attacker could potentially take control of the browser or access sensitive data. This poses a significant risk to corporate data security and individual privacy if users do not update their browser software.
Technical details
A vulnerability classified as an untrusted pointer dereference (CWE-822) exists in Microsoft Edge (Chromium-based). The flaw occurs when the application processes a pointer from an untrusted source without sufficient validation, leading to memory corruption. An unauthenticated remote attacker can exploit this by enticing a user to interact with malicious web content (User Interaction required). Successful exploitation allows the attacker to bypass security boundaries and elevate privileges (Scope: Changed), potentially leading to full system compromise. Microsoft has addressed this in version 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) < 150.0.4078.48
Timeline
- 2026-07-12: advisory: Initial advisory published by Microsoft and NVD.