Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
The vulnerability is caused by improper resource access using mismatched data types (type confusion). An attacker can craft appropriate input data transmitted over the network that forces the browser to treat an object in memory as a different type than it actually is. Such improper type operations can lead to memory corruption and ultimately arbitrary code execution in the browser context. Network vector (AV:N) with high attack complexity (AC:H) indicates that the exploit requires fulfilling additional technical conditions, however it does not require authentication or user interaction.
Successful exploitation of this vulnerability allows an attacker to remotely execute arbitrary code (RCE) on the victim's machine, potentially with escalation of impact beyond the browser container scope (S:C). This could lead to complete system compromise, data theft, or malicious software installation.
Patches available from the vendor must be applied immediately in accordance with Microsoft Security Response Center references at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289. It is recommended to enable automatic updates for Microsoft Edge browser.
Microsoft Edge (Chromium-based) — specific versions indicated in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HMicrosoft Edge
APPMicrosoft< 150.0.4078.48
Related vulnerabilities
Integer overflow w Skia w Google Chrome — sandbox escape
Heap buffer overflow w GPU w Google Chrome — sandbox escape
Eskalacja uprawnień w Microsoft Edge (Chromium) — CVE-2024-21326
Eskalacja uprawnień w Microsoft Edge (Chromium) — CWE-416 Use-After-Free
Microsoft Edge (Chromium) — Elevation of Privilege przez use-after-free