Description
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow (CWE-190) that occurs while handling certain numeric values in Microsoft Edge (Chromium-based). An attacker with network access can trigger this overflow and cause the browser to execute arbitrary code in the user’s process, potentially compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

Microsoft Edge (Chromium-based) is affected. No specific build or version information is disclosed, so all current installations of this browser that use the vulnerable Chromium engine should be considered at risk until a vendor patch is applied.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. Its EPSS score is reported as less than 1%, denoting a very low but non-zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalogue. The description that malicious code can be executed over a network suggests a network-based attack vector, though exact prerequisites are not specified in the CVE data.

Generated by OpenCVE AI on July 24, 2026 at 10:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version via Windows Update or by downloading the latest installer from the Microsoft Security Response Center.
  • If the browser cannot be updated immediately, block it from accessing external networks through firewall or proxy rules to reduce exposure.
  • Configure group policy or use a content-filtering solution to restrict Edge to approved sites and disable the browser until the security update is deployed.

Generated by OpenCVE AI on July 24, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-190
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T19:35:48.029Z

Reserved: 2026-06-26T17:45:44.853Z

Link: CVE-2026-57974

cve-icon Vulnrichment

Updated: 2026-07-06T11:34:51.814Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T10:30:09Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound