Microsoft Edge (Chromium-based) Type Confusion Vulnerability Leading to Remote Code Execution

Vulnerability

A type confusion vulnerability has been identified in Microsoft Edge (Chromium-based), specifically in version 150.0.4078.48. This vulnerability allows an unauthorized attacker to execute code remotely over the network. The issue arises from improper handling of resources, enabling exploitation by crafting deceptive elements that a user must interact with.

Impact

Exploitation of this vulnerability could lead to unauthorized remote code execution.

Reproduction

To reproduce this vulnerability, an attacker would need to host a specially crafted website designed to exploit the type confusion issue in Microsoft Edge (Chromium-based) version 150.0.4078.48. The attacker would then have to convince a user to visit the website, potentially through an email or message enticement, or by sending an attachment that prompts the user to open it.

Remediation

Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48 from the Microsoft Update Catalog.

Added: Jul 3, 2026, 9:34 PM
Updated: Jul 3, 2026, 9:34 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
4.0
remediation
7.7
relevance
8.7
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.