Input validation error in Microsoft Edge - CVE-2026-58292
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content or opening a specially crafted file. A remote attacker can host a specially crafted website or provide a specially crafted file to execute arbitrary code.
User interaction is required, and successful exploitation requires the user to visit an attacker-controlled webpage or open crafted content. Successful exploitation also requires preparing the target environment to improve exploit reliability, and the impact may extend beyond the vulnerable component's security scope.