Executive brief
Microsoft Edge is a web browser used by millions to access the internet. A missing authorization flaw allows an attacker to execute code remotely through the network without proper authentication, potentially compromising user data and system integrity.
Technical details
The vulnerability stems from missing authorization checks in Microsoft Edge (Chromium-based). An attacker can exploit this flaw over the network to execute arbitrary code with the privileges of the affected user. No user interaction or pre-authentication is required to trigger the vulnerability. The attack vector is network-based, making it remotely exploitable. Microsoft has published a security update to remediate this issue.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-04: disclosed