PT-2026-41712 · Microsoft · Edge
CVE-2026-45495
·
Published
2026-05-15
·
Updated
2026-06-22
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Edge versions prior to 148.0.3967.70
Description
A remote code execution issue exists in Microsoft Edge (Chromium-based) due to improper input validation within the browser's rendering pipeline and JavaScript engine. Specifically, the flaw involves directory traversal in the handling of feedback logs. An unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted webpage, leading to memory corruption, such as a buffer overflow, which allows the execution of arbitrary code with the privileges of the browser process. This issue can be combined with weak origin validation and cross-origin script injection to bypass the browser sandbox.
Recommendations
Update to version 148.0.3967.70.
Fix
DoS
RCE
Buffer Overflow
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Edge