Microsoft Edge (Chromium-based) Relative Path Traversal Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Microsoft Edge (Chromium-based) versions through 150.0.4078.48. This vulnerability arises from relative path traversal, which allows an unauthorized attacker to execute code over a network. Exploitation requires user interaction, such as opening a specially crafted file or visiting an attacker-controlled website.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Reproduction

To reproduce this vulnerability, a user must open a specially crafted file that exploits the relative path traversal flaw in Microsoft Edge. This can be done by hosting the file on a network share or through a website, and then convincing the user to access it.

Remediation

Users can download the security update for this vulnerability from the Microsoft Update Catalog.

Added: Jul 3, 2026, 9:40 PM
Updated: Jul 3, 2026, 9:40 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.6
remediation
7.7
relevance
8.8
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.