Description
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an attacker to externally control the file name or path used by Microsoft Edge (Chromium-based). Because this input is not sanitized, an adversary can cause Edge to resolve and process a malicious path, resulting in the execution of arbitrary code on the user’s system and compromising confidentiality, integrity, and availability. The weakness is identified as CWE‑73, which describes untrusted input influencing file system paths.

Affected Systems

Microsoft Edge (Chromium-based) – the CVE does not list a specific affected version, implying that all current releases of Edge may be vulnerable until an official update is issued.

Risk and Exploitability

The CVSS score of 8.1 reflects a high severity vulnerability. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over a network, such as a malicious web page or a crafted link that causes Edge to process a crafted file name or path. No additional prerequisites or conditions are detailed in the CVE data.

Generated by OpenCVE AI on July 21, 2026 at 09:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version released through Windows Update or the Microsoft Edge update channel to apply the vendor‑provided fix.
  • If an immediate update is not possible, configure Edge or the host group policy to restrict or block use of local file scheme URLs and disable access to arbitrary file paths until the patch is installed.
  • Enable Microsoft Defender SmartScreen or an equivalent web‑content filtering solution to block potentially malicious URLs that could trigger the exploitation.

Generated by OpenCVE AI on July 21, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-73
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:34:30.536Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58293

cve-icon Vulnrichment

Updated: 2026-07-06T16:38:37.190Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-73

    External Control of File Name or Path