Type Confusion in Microsoft Edge - CVE-2026-72984
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) when rendering a specially crafted webpage. A remote attacker can host a specially crafted webpage and convince a user to visit it to execute arbitrary code.
Successful exploitation could allow code execution within the browser renderer process. User interaction is required.