CVE-2026-85892
massLocal Privilege Elevation via Race Condition in Microsoft Edge (Chromium-based)
CVE-2026-85892 is a race condition (CWE-362) in Microsoft Edge (Chromium-based) in which concurrent execution using a shared resource is improperly synchronized. An attacker who already has authorized, low-privileged local access to a victim's machine can exploit timing windows in the browser's handling of the shared resource to elevate privileges locally; the high attack-complexity rating reflects that reliable exploitation requires precise timing. Successful exploitation gives the attacker high impact on confidentiality, integrity, and availability with scope change beyond the browser (CVSS 3.1 base score 7.8). Anyone running an affected Chromium-based Edge build on Windows (or macOS/Linux where applicable) is exposed, though the local attack vector means the attacker must first be on the system. There is no known public proof-of-concept, the flaw is not listed in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Update Microsoft Edge to the latest stable version immediately via Settings > About Microsoft Edge (which triggers the auto-updater) or your managed update channel, then confirm the build matches Microsoft's fixed release. Because exploitation requires existing local access, reinforce host hygiene: enforce least-privilege local accounts, avoid shared workstations, and monitor for anomalous child processes or privilege escalation attempts originating from Edge processes. No configuration workaround substitutes for applying the vendor patch.
| Microsoft Edge (Chromium-based) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.