Executive brief
Microsoft Edge is a web browser used by millions of users for accessing the internet. A flaw in its authorization checks allows an attacker to access sensitive information over a network without proper credentials, potentially exposing user data or browser functionality to unauthorized parties.
Technical details
This vulnerability is an incorrect authorization flaw in Microsoft Edge (Chromium-based) that enables information disclosure over a network. An unauthenticated attacker can exploit this by sending crafted network requests to bypass authorization checks and retrieve sensitive information. The attack vector is network-based and does not require user interaction or prior authentication. A patch is expected from Microsoft as part of their security updates.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-28: disclosed