CVE-2026-62904: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Published Aug 28, 2026
·Updated
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Other sources
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
— Microsoft
Affected Software
9 affected componentsFixes available
Microsoft Edge<152.0.4191.53
Microsoft Edge (Chromium-based)<152.0.4191.53
152.0.4191.53
Microsoft Edge Chromium<152.0.4191.53
Microsoft Edge for MAC<152.0.4191.52
152.0.4191.52
Microsoft Edge (Chromium-based)
Microsoft Edge for Linux<152.0.4191.52
152.0.4191.52
Microsoft Edge for Android<152.0.4191.52
152.0.4191.52
Microsoft Edge for iOS<152.0.4191.52
152.0.4191.52
Microsoft Edge for Windows<152.0.4191.52
152.0.4191.52
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.52
Event History
Aug 28, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
DescriptionAffected Software
Updated
via Microsoft·02:00 PM
SeverityAffected Software
Updated
via Microsoft·02:00 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionSeverity
Data Sourced
via NVD·08:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of attacker access is required to exploit this issue?
The vulnerability can be exploited remotely without prior privileges or authentication, but it requires user interaction.
2
What is the likely impact if exploitation succeeds?
Successful exploitation may disclose information and may also affect integrity. The supplied metrics indicate no availability impact.