VYPR
patchPublished Aug 28, 2026· Updated Aug 29, 2026· 1 source

Microsoft Edge: Batch of 7 CVEs patched, including High-severity RCE flaw

Key findings • Microsoft Edge: One high and six medium severity vulnerabilities disclosed on August 28, 2026. • Vulnerabilities include type confusion, LLM prompting issues, origin validation…

Key findings

  • Microsoft Edge: One high and six medium severity vulnerabilities disclosed on August 28, 2026.
  • Vulnerabilities include type confusion, LLM prompting issues, origin validation errors, use-after-free, path traversal, and authorization flaws.
  • Flaws affect both Chromium-based Edge and Edge for iOS.
  • All disclosed vulnerabilities have been patched by Microsoft.

On August 28, 2026, Microsoft released security updates addressing a batch of seven vulnerabilities in its Edge browser. The disclosures include one high-severity flaw and six medium-severity flaws, all patched on the same day. The vulnerabilities span various components of the Chromium-based browser and affect different attack vectors, including type confusion, improper input neutralization, origin validation errors, use-after-free, external control of file paths, and incorrect authorization.

One of the most critical vulnerabilities, CVE-2026-72984, is a high-severity "type confusion" flaw in the Chromium-based engine of Microsoft Edge. This vulnerability allows an unauthorized attacker to execute code remotely over a network, posing a significant risk to users.

Several medium-severity vulnerabilities were also disclosed:

  • CVE-2026-70331, affecting Edge for iOS, is an improper neutralization of input used for LLM prompting, enabling spoofing attacks.
  • CVE-2026-70309, an origin validation error in the Chromium-based engine, could allow an attacker to bypass security features.
  • CVE-2026-66798, a use-after-free vulnerability in the Chromium-based engine, also carries the risk of remote code execution.
  • CVE-2026-66324, an external control of file name or path vulnerability in the Chromium-based engine, could lead to spoofing.
  • CVE-2026-66323, an improper neutralization of parameter/argument delimiters in the Chromium-based engine, allows for remote code execution.
  • CVE-2026-62904, an incorrect authorization flaw in the Chromium-based engine, could permit an attacker to disclose sensitive information.

All seven vulnerabilities were addressed by Microsoft on August 28, 2026. Users are strongly advised to update their Microsoft Edge browser to the latest version to mitigate these security risks. The consistent patching of these diverse vulnerabilities highlights Microsoft's ongoing efforts to maintain the security posture of its browser.

This batch of vulnerabilities underscores the importance of timely patching for web browsers, as flaws can emerge across various components and impact different aspects of user security, from code execution to information disclosure and spoofing. Users should remain vigilant and ensure their browsers are updated to the most recent stable release.

Synthesized by Vypr AI