Executive brief
Microsoft Edge is a web browser used by millions of users to access online services and content. A type confusion vulnerability in Edge could allow an attacker to execute arbitrary code on a user's computer through a malicious webpage, potentially compromising user data, credentials, and system security without requiring user interaction beyond visiting the affected site.
Technical details
This vulnerability is a type confusion issue in Microsoft Edge's Chromium-based rendering engine, where an attacker can access resources using an incompatible type. The flaw allows remote code execution (RCE) when a victim visits a specially crafted webpage, with no additional user interaction required beyond browsing. The attack vector is network-based and does not require the user to be authenticated. An attacker can exploit this to execute arbitrary code with the privileges of the Edge process, leading to potential system compromise.
Affected products
- Microsoft Edge <unknown>
Timeline
- 2026-08-28: disclosed