Description
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofing via manipulated file path
Action: Apply patch
AI Analysis

Impact

An attacker can externally control a file name or path that Microsoft Edge (Chromium-based) interprets, enabling the attacker to spoof network resources. The vulnerability is a form of path traversal (CWE‑73) that lets an unauthorized actor pose as legitimate files or services, potentially deceiving users or intercepting traffic.

Affected Systems

All installed Microsoft Edge browsers based on the Chromium engine are potentially affected. No specific version range is listed, so any current release of Microsoft Edge (Chromium-based) should be considered at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium risk. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likelihood of exploitation depends on an attacker being able to supply a crafted file path that the browser processes; this could occur via malicious links or scripts that open Edge with such a path. While the attack vector is inferred to be remote, the lack of public exploit data suggests limited current exploitation risk, but the medium severity warrants prompt mitigation.

Generated by OpenCVE AI on August 28, 2026 at 21:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses the path control issue by following the official update guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66324).
  • Enable automatic updates for Microsoft Edge to ensure the patch is installed as soon as it becomes available.
  • If immediate patching is not possible, restrict Edge’s ability to load external file paths through local policy settings or use a web firewall to block suspicious URL patterns that could trigger the vulnerability.

Generated by OpenCVE AI on August 28, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft edge
CPEs cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:linux:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:mac:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft edge

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-73
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-16T16:26:53.668Z

Reserved: 2026-07-24T18:06:51.296Z

Link: CVE-2026-66324

cve-icon Vulnrichment

Updated: 2026-08-31T18:53:00.563Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T20:19:34.407

Modified: 2026-09-11T17:17:43.160

Link: CVE-2026-66324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:45:03Z

Weaknesses
  • CWE-73

    External Control of File Name or Path