Executive brief
Microsoft Edge is a web browser used by millions of users to browse the internet and access online services. An origin validation flaw allows attackers to bypass a security feature over the network, potentially enabling unauthorized access to sensitive features or user data that should be protected by browser security controls.
Technical details
The vulnerability is an origin validation error in Microsoft Edge (Chromium-based) that allows unauthorized attackers to bypass a security feature via network attack. The issue stems from improper validation of request origins, enabling an attacker to circumvent browser security mechanisms designed to protect against cross-origin attacks. The attack is network-reachable and requires no authentication or elevated privileges. An attacker can exploit this to bypass origin-based security controls, potentially gaining unauthorized access to protected functionality or data. Patches are expected to be available through Microsoft's standard security update process.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-28: disclosed