Junglewise Threat Intelligence

CVE-2026-85892: Microsoft Edge race condition in shared resource synchronization

CVE-2026-85892 · Severity: high · CVSS 7.8 · Published 2026-09-14

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users to access the internet and business applications. A race condition flaw in the browser's internal resource handling could allow a local attacker with authorized access to bypass security protections and gain elevated system privileges, potentially compromising the entire device.

Technical details

A race condition vulnerability exists in Microsoft Edge (Chromium-based) due to improper synchronization when accessing shared resources. An authorized local attacker can exploit this timing-dependent flaw to trigger a concurrent access condition, leading to privilege escalation. The attack requires local system access and is triggered during normal browser operation. Patches are expected to be available through Microsoft's standard security update cycle.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-09-14: disclosed

References

Related threats