CVE-2026-66323: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53
Event History
Frequently Asked Questions
Does an attacker need credentials or prior access to exploit this issue?
No. The CVSS vector indicates no privileges are required, and the attack can be initiated over the network.
Is user interaction required?
Yes. The CVSS vector specifies that user interaction is required, so exploitation depends on a user performing an action.
What is the expected security impact?
The issue is rated medium severity with a CVSS score of 5.4. It has low confidentiality and integrity impact, with no availability impact indicated.