Description
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-08-03
Score: 7.4 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a type‑confusion bug that allows an attacker to cause the browser to access a resource using an incompatible type. This flaw can lead to arbitrary code execution within the context of Microsoft Edge (Chromium‑based). The flaw is exploitable by an unauthorized attacker to run code on a system that opens the browser, potentially compromising confidentiality, integrity, and availability of the affected machine.

Affected Systems

The affected product is Microsoft Edge (Chromium‑based) as published by Microsoft. No specific version range is listed, so all installed instances of Microsoft Edge that use the Chromium engine are potentially vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity, and the vulnerability is exploitable over the network by an unauthenticated attacker. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote network exploit that does not require user interaction beyond visiting malicious content. The exploit would trigger the type confusion and result in arbitrary code execution inside the browser process.

Generated by OpenCVE AI on August 4, 2026 at 09:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update that addresses the type‑confusion issue
  • If the update cannot be applied, uninstall or disable Microsoft Edge to prevent exploitation
  • Configure corporate policies or endpoint protection to block or restrict use of vulnerable browsers until a fix is available

Generated by OpenCVE AI on August 4, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-843
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-20T17:00:45.266Z

Reserved: 2026-07-24T18:06:51.296Z

Link: CVE-2026-66321

cve-icon Vulnrichment

Updated: 2026-08-04T14:16:06.509Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T00:17:39.440

Modified: 2026-08-06T17:06:42.727

Link: CVE-2026-66321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:45:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')