Description
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-07-03
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium-based) contains an improper authorization flaw that lets an attacker bypass a built‑in security feature. The vulnerability, identified as CWE-285, allows a malicious actor to trigger functionality that should only be available after proper authorization, thereby enabling unauthorized actions within the browser context.

Affected Systems

The affected product is Microsoft Edge (Chromium-based) by Microsoft. No specific version ranges are listed, so all currently supported builds are considered potentially affected until a vendor patch is released.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. The EPSS score of less than 1% suggests a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be over a network, where crafted traffic can reach the Edge process and exploit the missing authorization check.

Generated by OpenCVE AI on July 21, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge release that contains the fix for the authorization bypass.
  • Limit network exposure of Edge by configuring firewall or network rules so that only trusted, authenticated traffic can reach the browser’s privileged interfaces.
  • Configure Edge policy settings to enforce authentication for any features that can be triggered remotely or disable those features entirely while a patch is pending.

Generated by OpenCVE AI on July 21, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Title Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:56:06.714Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57983

cve-icon Vulnrichment

Updated: 2026-07-06T11:48:09.002Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses