Description
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-12
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted pointer dereference flaw in Microsoft Edge (Chromium-based) allows an unauthenticated attacker to elevate privileges over a network. The weakness, classified as CWE-822, involves dereferencing a pointer that references data that has not been properly verified. Exploiting this flaw can allow an attacker to gain higher-level access on a target system, compromising confidentiality, integrity, and availability. Because specific version information is not provided, we infer that any Edge installation lacking the official patch is potentially vulnerable.

Affected Systems

Microsoft Edge (Chromium-based). All supported Edge releases published before the issuance of the patch are potentially vulnerable until the update is applied. No specific version numbers are listed. We infer that every unpatched Edge release falls within the affected scope due to the absence of version constraints.

Risk and Exploitability

The CVSS score of 8.3 signals high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploitation. An attacker must cause Edge to dereference an untrusted pointer. Attack prerequisites include an unpatched Edge installation and sufficient network access. Because the impact is not limited to a narrow version range, we infer that the vulnerability could affect all unpatched installations. If exploited, the attacker could elevate privileges on the host system, potentially gaining full control.

Generated by OpenCVE AI on July 29, 2026 at 08:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update that contains the fix for CVE-2026-58596
  • Restrict network exposure of Edge or the vulnerable component until the update is deployed
  • Enable Windows Defender Exploit Guard or apply appropriate Attack Surface Reduction rules to mitigate potential privilege‑elevation exploits

Generated by OpenCVE AI on July 29, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-822
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:27:46.627Z

Reserved: 2026-07-01T18:03:43.124Z

Link: CVE-2026-58596

cve-icon Vulnrichment

Updated: 2026-07-13T15:39:29.809Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:00:18Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference