Description
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-07-03
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a type confusion flaw (CWE‑843) in Microsoft Edge (Chromium‑based). It allows an attacker who can deliver a specially crafted resource over the network to instruct the browser to access the resource using an incompatible type, thereby bypassing a built‑in security feature. The description does not state that secrets are exposed or that privilege escalation is possible; however, the bypass could potentially enable additional attacks that rely on the compromised protection.

Affected Systems

All releases of Microsoft Edge (Chromium‑based) are potentially impacted, as the CVE data does not provide version exclusions. Until a fixed version is installed, any deployment of the browser may be vulnerable.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in CISA’s KEV catalog. The stated attack vector is a network-based delivery of malicious content; the attacker must successfully make the victim’s Edge browser process an incompatible resource in order to bypass the security feature.

Generated by OpenCVE AI on August 1, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge (Chromium‑based) to the latest release that incorporates the CVE‑2026‑58295 fix.
  • If a patch cannot be applied immediately, limit the browser’s exposure to external content that could trigger the type‑confusion logic, such as disabling related features or restricting content types when configuration permits.
  • Apply network controls, such as firewall rules or application layer filtering, to reduce the Edge browser’s exposure to potentially malicious sites that could deliver the crafted resource.

Generated by OpenCVE AI on August 1, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Title Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-843
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:53.944Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58295

cve-icon Vulnrichment

Updated: 2026-07-06T16:25:57.575Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:04.417

Modified: 2026-07-07T12:32:13.573

Link: CVE-2026-58295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')