CVE-2026-72984
massType Confusion Flaw in Microsoft Edge (Chromium-based) Allows Network RCE
CVE-2026-72984 is a type confusion bug (CWE-843) in the Chromium-based Microsoft Edge browser, in which the browser accesses a resource using an incompatible type. Per the CVSS vector, exploitation requires no privileges or special conditions but does require user interaction (UI:R), meaning an attacker would typically need the user to load attacker-crafted web content delivered over the network. Successful exploitation allows the unauthorized attacker to execute code, with high impact on confidentiality, integrity, and availability per the CVSS scoring. Any user running affected Chromium-based Edge builds is exposed; the source data does not enumerate specific affected versions. There is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Update Microsoft Edge to the latest stable-channel build via the browser's built-in updater and verify at edge://settings/help or edge://version; the source data does not specify the patched version number. Because exploitation requires user interaction with crafted content, caution with untrusted links and websites offers interim mitigation. Enterprises should confirm Edge auto-update is functioning fleet-wide given the high-severity code-execution impact.
| microsoft Edge (Chromium-based) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- edge chromium
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.