Description
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-07-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium‑based) contains an improper access control flaw (CWE‑284) that permits an unauthorized attacker to bypass a security feature that is enforced over a network connection. The flaw enables the attacker to perform actions normally protected by that feature, though the advisory does not enumerate the specific capabilities. Because the bypass undermines Edge’s security mechanism, the potential impact includes unauthorized execution of privileged actions or data access within the browser context.

Affected Systems

The vulnerability affects Microsoft Edge (Chromium‑based). No version constraints are listed in the advisory, so all installed instances of the Chromium‑based Edge browser are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.2 classifies the flaw as high severity; its EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog, suggesting no known large‑scale exploitation. Based on the description, the likely attack vector is remote over a network where an attacker can send crafted traffic to trigger the access‑control bypass. No public exploit is documented beyond routine network communication to the browser.

Generated by OpenCVE AI on July 26, 2026 at 16:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version with the vendor’s security patch when it becomes available.
  • If the browser is not required for user workflows, uninstall or disable Microsoft Edge to reduce attack surface.
  • Restrict Edge’s network access with firewall or network segmentation so it cannot reach sensitive internal resources.
  • Monitor for anomalous outbound traffic originating from Edge that could indicate exploitation attempts, and apply alerting where possible.

Generated by OpenCVE AI on July 26, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Title Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-28T21:24:07.673Z

Reserved: 2026-07-01T04:33:41.869Z

Link: CVE-2026-58525

cve-icon Vulnrichment

Updated: 2026-07-09T13:27:27.498Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:00:14Z

Weaknesses