CVE-2026-58525
edge_chromium: Improper Access Control (CVE-2026-58525)
highEPSS 0.5%
Affected
- microsoft/edge_chromium
lt *..150.0.4078.50
Description
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
microsoftedge_chromium
150.0.4078.50fixed from 150.0.4078.50Metrics
Show all metrics
Severity
high
76.77
no public PoC known
8.2
Published
2026-07-08 21:16 UTC
CWE-284
Weakness classes (CWE)
CWE-284Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-07-09 17:16 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:-:*:*:* versions up to (excluding) 150.0.4078.50
- Reference Type: Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58525 Types: Vendor Advisory