CVE-2026-45492Disclosure(microsoft / edge_chromium)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft edge_chromium systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edge_chromium

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-05-18); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
edge_chromium

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-05-18: 2Mentions · 2026-05-21: 1Mentions · 2026-06-04: 1Mentions · 2026-06-05: 2Mentions · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-05: 1Patch / Workaround · 2026-06-05: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-06: 105-1805-2106-0406-0506-06
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-182
Disclosure2
2026-05-211
Disclosure1
2026-06-041
Disclosure1
2026-06-052
Disclosure2
2026-06-061
General1
Full discourse7 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-329|CVE-2026-45492] (Pwn2Own) Microsoft Edge Origin Validation Error Security Bypass Vulnerability (CVSS 4.3; Credit: Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3)) https://www.zerodayinitiative.com/advisories/ZDI-26-329/

    Post summary

    The post announces a new CVE with basic technical details and links to an advisory that likely contains a PoC, but it does not provide exploit code, patches, or evidence of active exploitation.

    14036122.6K
    5.6K followersView on X
  • BnSnK@BunSnack
    Disclosure

    Orange Tsai (DEVCORE) found CVE-2026-45495 in Microsoft Edge — unvalidated file path in feedback log handling allows code execution in the logged-in user context. Patched June 4. Also: CVE-2026-45494, CVE-2026-45492. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495

    Post summary

    Orange Tsai disclosed a Microsoft Edge vulnerability (CVE‑2026‑45495) that allows local code execution due to an unvalidated file path, and the issue was patched on June 4. Additional related CVEs were noted but not detailed.

    0003025
    6 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    General

    Microsoft Edge Origin Validation Error Security Bypass Vulnerability (CVE-2026-45492) https://www.systemtek.co.uk/2026/06/microsoft-edge-origin-validation-error-security-bypass-vulnerability-cve-2026-45492/ via @SystemTek_UK

    Post summary

    The post announces CVE‑2026‑45492 as a Microsoft Edge origin‑validation bypass, but provides no further details on code, exploitation, or mitigation.

    0000040
    1.8K followersView on X
  • たるいひでと@TaruiHideto
    Disclosure

    CVE-2026-45494 https://www.zerodayinitiative.com/advisories/ZDI-26-330/ CVE-2026-45492 https://www.zerodayinitiative.com/advisories/ZDI-26-329/

    Post summary

    The text lists two CVE identifiers linked to Zeroday Initiative advisories, indicating new zero‑day disclosures, but provides no additional technical, exploit, or mitigation details.

    0000053
    544 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    Microsoft Edge Flaw CVE-2026-45492 Lets Attackers Bypass VBS https://thecybrdef.com/microsoft-edge-flaw-cve-2026-45492-lets-attackers-bypass-vbs/ #Cybertrending #Cybernewsdaily #Cybersecurity

    Post summary

    An announcement of a newly disclosed Microsoft Edge CVE (CVE-2026-45492) that may allow VBS bypass, with no further technical details, exploit code, patch information, or evidence of active exploitation provided.

    0000052
    9 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Microsoft Edge (CVE-2026-45492) https://vuldb.com/vuln/364485

    Post summary

    The post announces CVE‑2026‑45492 affecting Microsoft Edge and links to a vulnerability database, offering no further technical or mitigate information.

    0000085
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45492 Security Feature Bypass in Microsoft Edge Chromium-Based via Improper Input Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45492

    Post summary

    The post announces CVE-2026-45492, a security feature bypass in Microsoft Edge due to improper input validation. No additional details on PoC, exploit, or mitigation are provided.

    0000067
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftedge_chromium---

Explore more