Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege (Local)
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a race condition caused by improper synchronization of a shared resource in Microsoft Edge (Chromium-based). It allows a user who can run arbitrary code in Edge to gain higher local privileges on the affected system. The flaw is captured by CWE-362, indicating a race condition that can be exploited by an attacker who can repeatedly trigger the condition before the system resolves the state, thereby escalating privileges without needing external access.

Affected Systems

The affected vendor is Microsoft and the product is Microsoft Edge (Chromium-based). Specific affected editions or build numbers were not disclosed, so all exposed installation versions may be vulnerable until an official patch is released.

Risk and Exploitability

The CVSS score of 7.8 classifies this as a high severity flaw. The EPSS score of 0.00193 indicates a very low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is local, requiring an authorized attacker with the ability to run arbitrary code within Edge. Exploitation would involve creating a malicious web page or local content that triggers the race condition, thereby granting the attacker elevated privileges on the host. Because the flaw does not require network access and can be triggered by a normal user who can open a browser, the likelihood of exploitation remains low but could be higher in environments with many users or insufficient privilege controls.

Generated by OpenCVE AI on September 20, 2026 at 23:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Microsoft Edge to the latest patch as soon as it is released.
  • Restrict user accounts to the minimum privileges required to use Edge, preventing regular users from having elevated rights that could be abused.
  • Apply group policy or local security controls to limit Edge’s ability to execute privileged actions or access sensitive system resources.

Generated by OpenCVE AI on September 20, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
Title Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-362
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-01T22:52:40.389Z

Reserved: 2026-09-04T18:18:19.328Z

Link: CVE-2026-85892

cve-icon Vulnrichment

Updated: 2026-09-14T19:14:59.302Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T18:20:19.343

Modified: 2026-09-25T20:45:14.593

Link: CVE-2026-85892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')