Description
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper authorization weakness, classified as CWE‑285, located in Microsoft Edge’s Chromium engine. It enables an attacker to cause the browser to run arbitrary code, which operates with the same privileges that the Edge process itself holds. This can compromise the confidentiality, integrity, and availability of the system on which Edge is running.

Affected Systems

All installations of Microsoft Edge that use the Chromium engine are potentially affected. The CVE entry does not list specific product versions; consult the Microsoft security advisory for exact version details.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating high severity, and an EPSS score of less than 1% suggesting a very low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. The description notes that an attacker can trigger code execution over a network, and based on this information it is inferred that the attacker does not need local system access and can target any machine running Edge from an accessible network connection.

Generated by OpenCVE AI on August 1, 2026 at 20:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version available through Windows Update or the Edge update channel.
  • If an immediate update is not possible, block or restrict inbound connections to the Edge process with firewall rules or segment the network to limit the attacker’s ability to send malicious input.
  • Enable application whitelisting for the Edge executable and monitor system logs for indications of unauthorized code execution or abnormal activity.

Generated by OpenCVE AI on August 1, 2026 at 20:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:48.011Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58284

cve-icon Vulnrichment

Updated: 2026-07-06T11:29:28.981Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:03.057

Modified: 2026-07-07T05:16:54.207

Link: CVE-2026-58284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses