CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-58289

CVSS 9.0v3.1pub. 2026-07-03upd. 2026-07-07

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

🤖 AI Analysis
How it works

The vulnerability is caused by improper resource access using mismatched data types (type confusion). An attacker can craft appropriate input data transmitted over the network that forces the browser to treat an object in memory as a different type than it actually is. Such improper type operations can lead to memory corruption and ultimately arbitrary code execution in the browser context. Network vector (AV:N) with high attack complexity (AC:H) indicates that the exploit requires fulfilling additional technical conditions, however it does not require authentication or user interaction.

Impact

Successful exploitation of this vulnerability allows an attacker to remotely execute arbitrary code (RCE) on the victim's machine, potentially with escalation of impact beyond the browser container scope (S:C). This could lead to complete system compromise, data theft, or malicious software installation.

Mitigation & patch

Patches available from the vendor must be applied immediately in accordance with Microsoft Security Response Center references at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289. It is recommended to enable automatic updates for Microsoft Edge browser.

Who is affected

Microsoft Edge (Chromium-based) — specific versions indicated in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Edge

    APP
    Microsoft
    < 150.0.4078.48
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-6345CRITICAL9.6⚠ KEVPL ✓same product

Integer overflow w Skia w Google Chrome — sandbox escape

CVE-2022-4135CRITICAL9.6⚠ KEVPL ✓same product

Heap buffer overflow w GPU w Google Chrome — sandbox escape

CVE-2024-21326CRITICAL9.6PL ✓same product

Eskalacja uprawnień w Microsoft Edge (Chromium) — CVE-2024-21326

CVE-2023-35618CRITICAL9.6PL ✓same product

Eskalacja uprawnień w Microsoft Edge (Chromium) — CWE-416 Use-After-Free

CVE-2023-36735CRITICAL9.6PL ✓same product

Microsoft Edge (Chromium) — Elevation of Privilege przez use-after-free