Description
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-12
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted pointer dereference flaw in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. The vulnerability is a CWE-822 weakness that involves dereferencing a pointer without proper verification. Exploiting the flaw can give the attacker higher-level access on the target machine.

Affected Systems

Microsoft Edge (Chromium-based). All supported Edge releases published before the issuance of the patch are potentially vulnerable. No specific version numbers are listed, so all unpatched installations are considered affected.

Risk and Exploitability

The CVSS score of 8.3 signals high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based, requiring an unpatched Edge installation and sufficient network access. If successfully exploited, an attacker could elevate privileges on the host system.

Generated by OpenCVE AI on August 3, 2026 at 03:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update that contains the fix for CVE-2026-58596.
  • Reduce the exposure of the Edge browser to untrusted networks until the update is applied.
  • Enable Windows Defender Exploit Guard or apply appropriate Attack Surface Reduction rules to mitigate potential privilege-elevation exploits.

Generated by OpenCVE AI on August 3, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-822
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:06:24.130Z

Reserved: 2026-07-01T18:03:43.124Z

Link: CVE-2026-58596

cve-icon Vulnrichment

Updated: 2026-07-13T15:39:29.809Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-12T16:16:31.350

Modified: 2026-07-14T05:16:18.990

Link: CVE-2026-58596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:00:13Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference