CVE-2026-72984: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Edge - Chromium
Exploit Status
Not Exploited
Exploitation Likelihood
More Likely
Patch Tuesday
2026-Aug
Released
2026-08-28

Description

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability? An unauthenticated attacker could host a specially crafted webpage and convince a user to visit it using an affected version of Microsoft Edge. Successful exploitation could allow the attacker to execute code within the browser renderer process. User interaction is required. What is the version information for this release? Microsoft Edge Version Date Released Based on Chromium Version 152.0.4191.53 08/28/2026 152.0.7977.64/.65

Affected Products (1)

Browser

  • Microsoft Edge (Chromium-based)

Acknowledgments

<a href="https://x.com/rewhiles">Nguyen Thanh Dat</a> with <a href="https://x.com/vcslab">Viettel Cyber Security</a>

Revision History

  • 2026-08-28: Information published.