
XSS2RCE in Edge + Microsoft Store (2022). Forgotten Web APIs enabled RCE on any signed-in device; all now retired. https://jinmo.github.io/blog/2026/05/10/cve-2022-33649-entrypoint-to-push-to-install.html https://t.co/LiMwuA3Cuc
Post summary
The blog post announces that the XSS2RCE vulnerability affecting Edge and Microsoft Store has been mitigated by retiring the responsible Web APIs, making the issue no longer exploitable.
