Description
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A time‑of‑check to time‑of‑use (toctou) race condition in Microsoft Edge for Android allows an attacker to inject and execute code without user interaction. The flaw permits abuse of a network‑initiated race, letting an attacker bypass intended browser checks and run arbitrary code within the Edge process, potentially compromising the entire device.

Affected Systems

Microsoft Edge (Chromium‑based) for Android is affected. No specific version numbers are listed in the advisory, so any installation that has not incorporated the latest Microsoft Edge update is presumed vulnerable. The vulnerability is limited to the Android platform and does not affect other browsers or operating systems.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity, while the EPSS score of <1% indicates a low probability of exploitation at present. The issue is not listed in CISA’s KEV catalog, meaning no public exploit has been observed. The description and CWE‑367 suggest that a remote attacker can trigger the race condition using crafted network traffic directed at Edge without requiring the user to open a malicious link or provide input.

Generated by OpenCVE AI on July 17, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update for Android that contains the vendor fix for the race condition.
  • If a patch is not yet available, block or restrict Edge’s inbound traffic or limit its network access to trusted networks only.
  • Monitor the device for abnormal processes or signs of unauthorized code execution and apply any subsequent security updates promptly.

Generated by OpenCVE AI on July 17, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge for Android Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-367
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:34:34.054Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58299

cve-icon Vulnrichment

Updated: 2026-07-06T16:32:11.160Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T09:45:04Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition