Description
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper authorization flaw, classified as CWE-285, in Microsoft Edge's Chromium engine. An attacker who can craft malicious network traffic can compel the browser to run arbitrary code. This gives the attacker the ability to execute code on the machine with whatever privileges the Edge process runs under.

Affected Systems

All installations of Microsoft Edge that use the Chromium engine are potentially vulnerable. The CVE data does not specify which exact versions are affected; consult the Microsoft security advisory for detailed version information.

Risk and Exploitability

With a CVSS score of 8.3 the flaw is high severity, and the EPSS score of less than 1% indicates a very low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. A remote attacker with network access to a device running Edge can exploit this flaw through crafted network traffic.

Generated by OpenCVE AI on July 21, 2026 at 09:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version available through Windows Update or the Edge update channel.
  • If an immediate update is not possible, block or restrict inbound connections to the Edge process with firewall rules or network segmentation to limit the attacker’s ability to send malicious input.
  • Enable application whitelisting for the Edge executable and monitor system logs for indicators of unauthorized code execution or abnormal activity.

Generated by OpenCVE AI on July 21, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:36.547Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58284

cve-icon Vulnrichment

Updated: 2026-07-06T11:29:28.981Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses