Type Confusion in Microsoft Edge - CVE-2026-58295

 

Type Confusion in Microsoft Edge - CVE-2026-58295

Published: July 17, 2026


Vulnerability identifier: #VU138366
CSH Severity: High
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58295
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass a security feature.

The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website to bypass a security feature.

Successful exploitation can allow malicious JavaScript code to read information in the victim's browser associated with the vulnerable URL. User interaction is required to view the crafted content.


Affected software

Microsoft Edge

How to mitigate CVE-2026-58295

Install security update from vendor's website.

Microsoft Edge - update to 150.0.4078.48

External References

Related Security Bulletins