CVE-2026-72984

8.8

Microsoft · Microsoft Edge (Chromium-based)

A type confusion vulnerability in Microsoft Edge (Chromium-based) allows an unauthenticated remote attacker to execute arbitrary code.

Executive summary

A critical type confusion vulnerability in Microsoft Edge (Chromium-based) allows unauthenticated remote attackers to achieve arbitrary code execution.

Vulnerability

The software suffers from a type confusion flaw (CWE-843) that occurs when an application accesses a resource using an incompatible type. This vulnerability allows an unauthenticated attacker to execute code over a network by leveraging memory corruption.

Business impact

The ability for an unauthorized remote attacker to execute arbitrary code represents a severe compromise of system integrity and confidentiality. Given the high CVSS score of 8.8, this flaw poses a significant risk of full system takeover, potential lateral movement within the network, and the exfiltration of sensitive data.

Remediation

Immediate Action: Update Microsoft Edge (Chromium-based) to version 152.0.4191.53 or later immediately to resolve the memory corruption vulnerability.

Proactive Monitoring: Review browser logs and endpoint detection system alerts for unusual process execution patterns or unexpected browser crashes that may indicate exploitation attempts.

Compensating Controls: Implement browser-based security policies, such as disabling unnecessary plugins or restricting the execution of untrusted scripts, to reduce the attack surface until updates are applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of this remote code execution flaw, organizations should prioritize patching all instances of Microsoft Edge to the remediated version. Security teams must ensure that automatic updates are enabled and verify compliance across all managed endpoints to mitigate the risk of exploitation.

More Microsoft CVEs

Sources