CVE-2026-85892: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.66
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on the affected system and have local access. The issue is not described as remotely exploitable.
What level of access could exploitation provide?
Successful exploitation can allow local elevation of privilege. The supplied impact information indicates potential high impact to confidentiality, integrity, and availability.
How difficult is exploitation?
Exploitation requires high attack complexity and low privileges. It also does not require user interaction.