Description
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑release flaw in Microsoft Edge (Chromium-based) classified as CWE‑672 allows an attacker to read data that should no longer be accessible after the resource has been released. The vulnerability can result in information disclosure over a network, potentially exposing sensitive or confidential material the user did not intend to share.

Affected Systems

Microsoft Edge (Chromium-based) is the affected product. No specific version ranges are provided in the advisory, so all currently supported releases are potentially vulnerable until Microsoft releases a patched build.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Information may be disclosed over a network; the likely attack vector involves delivering malicious content or otherwise triggering the use‑after‑release condition in a running Edge instance, which could require user interaction or remote content delivery, although the exact path is not detailed.

Generated by OpenCVE AI on July 21, 2026 at 09:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that fixes CVE‑2026‑58291.
  • Disable or block unsupported extensions or legacy features that could trigger the vulnerable API to reduce exposure.
  • Use network segmentation or firewall rules to isolate Edge clients from sensitive resources, limiting the scope of potential data disclosure.
  • Monitor outbound connections from Edge for anomalous data transfer that could indicate exploitation.

Generated by OpenCVE AI on July 21, 2026 at 09:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Title Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-672
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:40.470Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58291

cve-icon Vulnrichment

Updated: 2026-07-06T15:29:25.504Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-672

    Operation on a Resource after Expiration or Release