Description
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Published: 2026-08-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a buffer over‑read in Microsoft Edge (Chromium‑based) that can allow an authorized attacker to execute code remotely. The weakness corresponds to CWE‑126, which describes situations where insufficient bounds checking can lead to memory corruption or code execution. If exploited, the attacker could run arbitrary code in the context of the application, potentially gaining control over the local system, accessing confidential information, or further propagating malware.

Affected Systems

Microsoft Edge (Chromium‑based) is listed as the affected product. Specific version information is not provided in the available data, so all released builds of Edge could be vulnerable until a fixed update is issued.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity for the vulnerability, and the EPSS score is not available, suggesting limited data on current exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be a network‑based interaction that requires an authorized attacker, as the description states the attacker must be able to interact over a network. Given the medium score and the lack of known active exploitation, the risk is moderate but still warrants prompt attention.

Generated by OpenCVE AI on August 4, 2026 at 09:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Edge security update that fixes CVE‑2026‑66312 via Windows Update or by downloading the latest patch from the Microsoft Security Response Center.
  • Ensure the host operating system is fully updated, because Edge updates are distributed through Windows patches and a recent OS update may bundle the Edge fix.
  • Implement network segmentation or application whitelisting to limit the ability of an authorized attacker to reach Edge through exposed ports or services, thereby reducing the attack surface for this vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 09:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-126
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-24T21:00:48.480Z

Reserved: 2026-07-24T18:06:51.295Z

Link: CVE-2026-66312

cve-icon Vulnrichment

Updated: 2026-08-04T14:15:56.986Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:38.510

Modified: 2026-08-06T17:01:48.057

Link: CVE-2026-66312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:45:03Z

Weaknesses