Executive brief
Microsoft Edge is a web browser used by millions of users for accessing websites and web applications. This vulnerability allows an attacker to execute malicious code remotely through improper handling of command-line arguments, potentially compromising user systems and data.
Technical details
This vulnerability stems from improper neutralization of parameter and argument delimiters in Microsoft Edge (Chromium-based). The flaw allows an unauthorized attacker to execute arbitrary code over a network without requiring authentication. The attack vector is network-based, meaning an attacker can exploit this remotely. Microsoft has released patches to address this issue.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-28: disclosed
- 2026-08-28: advisory