Medium severity4.2NVD Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
CVE-2026-55945
CVE-2026-55945
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
Affected products
2Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55945nvdVendor Advisory
News mentions
3- BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major BrowsersCyber Security News · Sep 19, 2026
- BragJack Attack Can Turn a Browser's Agentic AI Against ItDark Reading · Sep 16, 2026
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and ClaudeThe Hacker News · Sep 16, 2026