Description
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-11
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper deserialization of untrusted data within Microsoft Edge (Chromium-based). The flaw permits an attacker to execute arbitrary code, leading to full system compromise. The weakness is classified as CWE‑502, indicating insecure handling of serialized objects. The impact is therefore the loss of confidentiality, integrity, and availability for any affected system that runs the vulnerable browser.

Affected Systems

The affected product is Microsoft Edge (Chromium-based). No specific version information is listed in the CNA data, so any installation of the Chromium‑based Edge that remains unpatched is potentially vulnerable.

Risk and Exploitability

The CVSS score is 8.3, placing this vulnerability in the high severity range. The EPSS score is less than 1%, suggesting that the likelihood of exploitation is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog, indicating no known weaponized exploitation in the wild at the time of this analysis. The likely attack vector is remote, via network access to the victim’s machine that hosts Edge; an unauthorized attacker could feed a crafted serialized payload to the browser to trigger execution.

Generated by OpenCVE AI on August 1, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update via Windows Update or the Microsoft Update Catalog. Inform users that the update includes a critical patch for insecure deserialization.
  • Enable Windows Defender Exploit Guard to block execution of suspicious code and deserialization attacks. Configure policy to monitor for anomalous Edge behavior.
  • Limit Edge exposure to untrusted networks by enforcing stricter firewall rules or by disabling the browser entirely on workstations that do not require internet browsing.

Generated by OpenCVE AI on August 1, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:27:22.074Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58281

cve-icon Vulnrichment

Updated: 2026-07-13T14:03:10.208Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:30:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data