Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
How could an attacker exploit this vulnerability? An unauthenticated attacker could host a specially crafted webpage and convince a user to visit it using an affected version of Microsoft Edge. Successful exploitation could allow the attacker to execute code within the browser renderer process. User interaction is required. What is the version information for this release? Microsoft Edge Version Date Released Based on Chromium Version 152.0.4191.53 08/28/2026 152.0.7977.64/.65
<a href="https://x.com/rewhiles">Nguyen Thanh Dat</a> with <a href="https://x.com/vcslab">Viettel Cyber Security</a>