Description
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a type‑confusion flaw in Microsoft Edge (Chromium‑based). The browser incorrectly treats an object as a different type than intended, allowing an attacker who can deliver malicious content over a network to execute arbitrary code on the user’s device. The issue is classified as CWE‑843 and provides remote code execution capabilities that can compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

Any installation of Microsoft Edge (Chromium‑based) on supported platforms is potentially vulnerable until a vendor update is applied. The CVE entry does not specify a affected release number, so all current releases of Edge that have not been patched are at risk. This includes Windows, macOS, and Linux builds.

Risk and Exploitability

The assigned CVSS score of 8.3 marks the vulnerability as high severity, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. Edge is not listed in CISA’s KEV catalog, meaning no confirmed exploits are known yet. Based on the description, the likely attack vector requires an attacker to deliver malicious web content to a user, exploiting the type‑confusion flaw to trigger remote code execution. If successful, the attacker could gain full control over the victim’s system.

Generated by OpenCVE AI on July 21, 2026 at 09:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update that contains the fix for CVE‑2026‑58285.
  • Configure Windows Update or group policy to enable automatic updates for Microsoft Edge so that future patches are applied without manual intervention.
  • Implement enterprise endpoint protection and web‑content filtering to detect and block malicious pages or payloads that could trigger the type‑confusion flaw while a patch is pending.

Generated by OpenCVE AI on July 21, 2026 at 09:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-843
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:37.157Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58285

cve-icon Vulnrichment

Updated: 2026-07-06T11:27:22.869Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')