CVE-2026-72984: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53
Event History
Frequently Asked Questions
What does an attacker need to do to exploit this issue?
The attacker can attempt exploitation over a network without needing prior privileges or authentication. User interaction is required, so exploitation depends on convincing a user to interact with attacker-controlled content.
What is the potential impact if exploitation succeeds?
Successful exploitation can allow code execution and may affect confidentiality, integrity, and availability. The supplied severity vector rates all three impact categories as high.
Are systems running Microsoft Edge potentially exposed by default?
The available data identifies Microsoft Edge and Microsoft Edge (Chromium-based) as affected, but it does not state which versions or configurations are vulnerable. It also does not provide any indication that a non-default feature or configuration is required.