PT-2026-41712 · Microsoft · Edge

CVE-2026-45495

·

Published

2026-05-15

·

Updated

2026-06-22

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Edge versions prior to 148.0.3967.70
Description A remote code execution issue exists in Microsoft Edge (Chromium-based) due to improper input validation within the browser's rendering pipeline and JavaScript engine. Specifically, the flaw involves directory traversal in the handling of feedback logs. An unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted webpage, leading to memory corruption, such as a buffer overflow, which allows the execution of arbitrary code with the privileges of the browser process. This issue can be combined with weak origin validation and cross-origin script injection to bypass the browser sandbox.
Recommendations Update to version 148.0.3967.70.

Fix

DoS

RCE

Buffer Overflow

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09757
CVE-2026-45495
ZDI-26-331

Affected Products

Edge