SB2026083123 - Multiple vulnerabilities in Microsoft Edge



SB2026083123 - Multiple vulnerabilities in Microsoft Edge

Published: August 31, 2026

Security Bulletin ID SB2026083123
CSH Severity
High
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 14% Medium 57% Low 29%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Race condition (CVE-ID: CVE-2026-58616)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) when handling attacker-controlled web content and autofill activation. A remote user can craft deceptive or invisible form elements and convince the victim to visit a specially crafted webpage to disclose sensitive information.

User interaction is required: the victim must visit an attacker-controlled webpage and perform two sequential taps that cause autofill to activate.


2) Incorrect authorization (CVE-ID: CVE-2026-62904)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to incorrect authorization in Microsoft Edge (Chromium-based) when handling autofill activation on an attacker-controlled webpage. A remote attacker can cause the user to visit a crafted webpage and perform two tap gestures to disclose sensitive information.

User interaction is required to visit the attacker-controlled webpage and trigger autofill with two tap gestures.


3) Improper Neutralization of Parameter/Argument Delimiters (CVE-ID: CVE-2026-66323)

CWE-ID: CWE-141 - Improper Neutralization of Parameter/Argument Delimiters

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute code.

The vulnerability exists due to improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) when processing attacker-controlled web content. A remote attacker can cause the victim to visit a crafted webpage and perform two tap gestures to execute code.

User interaction is required for autofill to activate.


4) External Control of File Name or Path (CVE-ID: CVE-2026-66324)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform spoofing.

The vulnerability exists due to external control of file name or path in Microsoft Edge (Chromium-based) when processing an attacker-controlled webpage. A remote attacker can craft a webpage that triggers autofill after user interaction to perform spoofing.

User interaction is required: the user must visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate.


5) Use-after-free (CVE-ID: CVE-2026-66798)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute code.

The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a malicious webpage and induce the victim to visit it to execute code.

User interaction is required, including visiting an attacker-controlled webpage and performing two tap gestures that cause autofill to activate.


6) Use-after-free (CVE-ID: CVE-2026-70341)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) when processing specially crafted web content. A remote user can trigger specially crafted activity in the affected browser process to execute arbitrary code.

Successful exploitation requires existing ability to execute JavaScript in the affected Microsoft Edge process and can lead to code execution beyond the browser's security scope.


7) Type Confusion (CVE-ID: CVE-2026-72984)

CWE-ID: CWE-843 - Type confusion

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering a specially crafted webpage. A remote attacker can host a specially crafted webpage and convince a user to visit it to execute arbitrary code.

Successful exploitation could allow code execution within the browser renderer process. User interaction is required.


Remediation

Install update from vendor's website.