Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a...
Description
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Microsoft
PRODUCT: Edge (Chromium-based)
AFFECTED_VERSIONS: Microsoft Edge version prior to 150.0.4078.99
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An information disclosure vulnerability in Microsoft Edge (Chromium-based) allows unauthorized remote attackers to access sensitive system files or directories via crafted HTTP requests.
Executive Summary:
An information disclosure vulnerability in Microsoft Edge (Chromium-based) could allow remote attackers to gain unauthorized access to sensitive system resources.
Vulnerability Details
CVE-ID: CVE-2026-57990
Affected Software: Microsoft Edge (Chromium-based)
Affected Versions: Microsoft Edge version prior to 150.0.4078.99
Vulnerability: This vulnerability involves improperly configured access controls that permit unauthorized, unauthenticated attackers to disclose information over a network. The flaw allows external parties to probe for accessible directories or files by bypassing standard authentication mechanisms.
Business Impact
Successful exploitation allows an attacker to retrieve sensitive system information, which may lead to further system compromise or unauthorized data exposure. Given the CVSS score of 7.4, this vulnerability represents a high risk to organizational data confidentiality, especially if the browser is used to access internal corporate environments.
Remediation Plan
Immediate Action: Update Microsoft Edge to version 150.0.4078.99 or later immediately to apply the vendor-supplied security patches.
Proactive Monitoring: Review web server and network access logs for anomalous HTTP requests targeting system directories or unexpected recursive file access patterns.
Compensating Controls: Ensure that Web Application Firewalls (WAF) are configured to block requests containing directory traversal sequences or suspicious path probing patterns.
Exploitation Status
Public Exploit Available: False
Analyst Notes: As of July 27, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its ability to bypass authentication for sensitive resource access, making timely patching essential.
Analyst Recommendation
This vulnerability presents a significant risk to data privacy and system integrity. IT administrators must prioritize the deployment of the 150.0.4078.99 update across all endpoints to remediate the underlying configuration flaw and prevent potential information disclosure.