Description
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-08-11
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a type confusion flaw that allows an attacker with network access to craft a malicious resource that, when processed by Microsoft Edge (Chromium-based), results in arbitrary code execution. This flaw exposes users to complete compromise of their local environment, permitting the attacker to read, modify or delete data, install malware, or gain persistence. The weakness is identified as CWE‑843: Type Confusion.

Affected Systems

The flaw affects Microsoft Edge (Chromium-based) across all current installations where the vulnerable code path has not been patched. No specific version ranges are provided, so all iterations that contain the unpatched code are susceptible.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the near term, especially since the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the attack vector would be remote, typically via a malicious web page or crafted content that sends a specially formatted payload to the browser. Because the flaw involves a type confusion, it likely requires the attacker to embed a specially formatted payload; thus, the exploitation prerequisites include network connectivity to the targeted client and a user interacting with the malicious content. The combination of moderate severity and low exploitation probability means that while the damage could be complete if exploited, the risk of an attack in the current landscape is relatively low.

Generated by OpenCVE AI on August 12, 2026 at 14:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update that includes the fix.
  • If an immediate update is unavailable, block or restrict access to untrusted web content by using enterprise browser controls or policy settings that limit the execution of potentially malicious scripts.
  • Monitor for anomalous activity such as unexpected process creation or network connections from Edge and investigate any incidents promptly.

Generated by OpenCVE AI on August 12, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-843
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:23.406Z

Reserved: 2026-08-04T00:04:56.037Z

Link: CVE-2026-70339

cve-icon Vulnrichment

Updated: 2026-08-12T13:35:35.258Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T20:18:44.243

Modified: 2026-08-17T18:59:25.273

Link: CVE-2026-70339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T14:30:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')