Executive brief
Microsoft Edge is a web browser used by millions of users to access web services and content. A buffer over-read vulnerability in the Chromium rendering engine could allow an authorized attacker to execute malicious code on a user's computer when they visit a specially crafted website or access malicious network content.
Technical details
The vulnerability is a buffer over-read flaw in Microsoft Edge's Chromium-based rendering engine. This memory safety issue occurs when the browser reads beyond allocated buffer boundaries during processing of malformed data. An attacker with network access can craft malicious content (e.g., a webpage or network packet) that triggers the over-read, potentially corrupting memory and achieving remote code execution. The vulnerability requires the user to visit or interact with attacker-controlled content and affects multiple versions of Microsoft Edge.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-04: disclosed