Description
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-07-03
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium-based) contains an improper authorization flaw that lets an attacker bypass a built‑in security feature. The vulnerability, identified as CWE-285, allows a malicious actor to trigger functionality that should only be available after proper authorization, thereby enabling unauthorized actions within the browser context.

Affected Systems

The affected product is Microsoft Edge (Chromium-based) by Microsoft. No specific version ranges are listed, so all currently supported builds are considered potentially affected until a vendor patch is released.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1% suggests a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over a network, where crafted traffic can reach the Edge process and exploit the missing authorization check.

Generated by OpenCVE AI on August 1, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest release that contains the fix for the authorization bypass.
  • Restrict network traffic to the Edge process through firewall or network segmentation to limit exposure of privileged interfaces.
  • Use Edge policy settings to require authentication for any remote‑triggerable features or disable those features entirely while a patch is pending.

Generated by OpenCVE AI on August 1, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Title Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:16:16.642Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57983

cve-icon Vulnrichment

Updated: 2026-07-06T11:48:09.002Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:01.433

Modified: 2026-07-07T15:15:02.530

Link: CVE-2026-57983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses