Description
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
Published: 2026-08-03
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium-based) contains an origin validation error that allows an unauthorized user to tamper locally with the browser or its underlying data. This flaw enables modification of local resources or potentially the execution of unintended code, which could lead to data compromise or privilege escalation. The vulnerability aligns with CWE-346: Incorrect Privilege Management.

Affected Systems

All versions of Microsoft Edge (Chromium-based) are affected; specific version ranges are not disclosed in the advisory.

Risk and Exploitability

The CVSS score is 6.8, indicating a moderate to high risk. Exploitation likelihood is unclear due to the absence of an EPSS score, and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. The attack vector is inferred to be local, meaning an attacker would need unauthenticated local access to the affected machine. Overall, the risk is significant for environments where Edge is permitted to run untrusted content.

Generated by OpenCVE AI on August 4, 2026 at 20:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that includes the origin validation fix via Windows Update or the Microsoft Edge update channel.
  • Ensure that automatic updates for Microsoft Edge are enabled so that future security patches are applied promptly.
  • Enforce an Edge group policy or whitelist configuration that restricts local file access and limits browsing to approved sites to mitigate the risk until the patch can be applied.

Generated by OpenCVE AI on August 4, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
Title Microsoft Edge (Chromium-based) Tampering Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:02:04.508Z

Reserved: 2026-07-24T18:06:51.295Z

Link: CVE-2026-66313

cve-icon Vulnrichment

Updated: 2026-08-04T15:31:17.640Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:38.647

Modified: 2026-08-06T17:02:39.677

Link: CVE-2026-66313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:45:03Z

Weaknesses