CVE-2026-70309: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published Aug 28, 2026
·Updated
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Other sources
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft Microsoft Edge
Microsoft Edge (Chromium-based)<150.0.4078.65
150.0.4078.65
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.4078.65
Event History
Aug 28, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require an authenticated account or user interaction?
No privileges are required, but user interaction is required. The vulnerability is reachable over the network and has low attack complexity.
2
What is the expected impact if exploitation succeeds?
The rated impact is limited confidentiality and limited integrity impact. No availability impact is indicated.