CVE-2026-66312: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Jul 31, 2026
·Updated
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Other sources
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft Edge (Chromium-based)<151.0.4129.59
151.0.4129.59
Microsoft Edge<151.0.4129.59
Microsoft Edge Chromium<151.0.4129.59
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.59
Event History
Jul 31, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
DescriptionAffected Software
Aug 3, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionSeverity
Aug 4, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-66312?
CVE-2026-66312 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-66312?
To fix CVE-2026-66312, ensure that you are using the latest version of Microsoft Edge (Chromium-based).
3
What type of vulnerability is CVE-2026-66312?
CVE-2026-66312 is identified as a remote code execution vulnerability.
4
Who is affected by CVE-2026-66312?
CVE-2026-66312 affects users of Microsoft Edge (Chromium-based) who may be targeted by authorized attackers.
5
What can an attacker do with CVE-2026-66312?
An attacker exploiting CVE-2026-66312 can execute code remotely over a network.