ZeroHour

CVE-2026-85892

mass

Local Privilege Elevation via Race Condition in Microsoft Edge (Chromium-based)

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-85892 is a race condition (CWE-362) in Microsoft Edge (Chromium-based) in which concurrent execution using a shared resource is improperly synchronized. An attacker who already has authorized, low-privileged local access to a victim's machine can exploit timing windows in the browser's handling of the shared resource to elevate privileges locally; the high attack-complexity rating reflects that reliable exploitation requires precise timing. Successful exploitation gives the attacker high impact on confidentiality, integrity, and availability with scope change beyond the browser (CVSS 3.1 base score 7.8). Anyone running an affected Chromium-based Edge build on Windows (or macOS/Linux where applicable) is exposed, though the local attack vector means the attacker must first be on the system. There is no known public proof-of-concept, the flaw is not listed in CISA's KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Update Microsoft Edge to the latest stable version immediately via Settings > About Microsoft Edge (which triggers the auto-updater) or your managed update channel, then confirm the build matches Microsoft's fixed release. Because exploitation requires existing local access, reinforce host hygiene: enforce least-privilege local accounts, avoid shared workstations, and monitor for anomalous child processes or privilege escalation attempts originating from Edge processes. No configuration workaround substitutes for applying the vendor patch.

Affected
Microsoft Edge (Chromium-based)
Estimated exposure
mass≈1 billion+ devices potentially exposed (Edge is the default preinstalled browser on Windows 10/11) — Microsoft Edge ships as the default browser on Windows 10 and Windows 11, which run on roughly 1.4 billion monthly-active devices, so the install base is on the order of a billion — though practical risk is limited by the local-access…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.