CVE-2026-45495Disclosure(microsoft / edge_chromium)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft edge_chromium systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35CWE-20CWE-94CWE-119

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edge_chromium

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 17 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • General: 6 classified signals
  • Peaked 3d ago at 5 mentions (2026-06-05); latest day: 1
  • 17 total mentions across 10 days

Affected systems

Vendors
Products
edge_chromium

Deep dive

Activity timeline17 mentions / 10d
01345Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1Mentions · 2026-05-25: 2Mentions · 2026-05-31: 1Mentions · 2026-06-04: 1Mentions · 2026-06-05: 5Mentions · 2026-06-07: 3Mentions · 2026-06-12: 1Mentions · 2026-06-22: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-07: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-06-05: 3Patch / Workaround · 2026-06-07: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-25: 2Technical Details · 2026-06-04: 1Technical Details · 2026-06-05: 3Technical Details · 2026-06-07: 3Technical Details · 2026-06-12: 105-1805-1905-2105-2505-3106-0406-0506-0706-1206-22
Signal classification3 categories
Disclosure
847.1%
General
635.3%
Patch
317.6%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-181
General1
2026-05-191
Disclosure1
2026-05-211
General1
2026-05-252
Disclosure2
2026-05-311
General1
2026-06-041
Disclosure1
2026-06-055
Disclosure1General2Patch2
2026-06-073
Disclosure2Patch1
2026-06-121
Disclosure1
2026-06-221
General1
Full discourse17 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-331|CVE-2026-45495] (Pwn2Own) Microsoft Edge Feedback Log File Handling Directory Traversal Remote Code Execution Vulnerability (CVSS 7.5; Credit: Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3)) https://www.zerodayinitiative.com/advisories/ZDI-26-331/

    Post summary

    A new vulnerability (CVE-2026-45495) affecting Microsoft Edge's feedback log file handling has been disclosed, identified as a directory traversal Remote Code Execution flaw with a CVSS score of 7.5; no exploit tools, active attacks, or patches are mentioned.

    012059175.9K
    5.6K followersView on X
  • elhacker.NET@elhackernet
    Patch

    Vulnerabilidad en Microsoft Edge permite ejecución de código remoto Microsoft ha lanzado una actualización de seguridad para corregir una vulnerabilidad crítica en Microsoft Edge CVE-2026-45495 https://blog.elhacker.net/2026/06/vulnerabilidad-en-microsoft-edge.html

    Post summary

    The text announces that Microsoft Edge is vulnerable to a remote code execution flaw (CVE-2026-45495) and informs readers that Microsoft has released a security update to address the issue.

    217057103.7K
    141.0K followersView on X
  • BnSnK@BunSnack
    Disclosure

    Orange Tsai (DEVCORE) found CVE-2026-45495 in Microsoft Edge — unvalidated file path in feedback log handling allows code execution in the logged-in user context. Patched June 4. Also: CVE-2026-45494, CVE-2026-45492. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495

    Post summary

    Researcher identified a file path validation flaw in Microsoft Edge that could enable code execution, which was patched on June 4.

    0003025
    6 followersView on X
  • たるいひでと@TaruiHideto
    Patch

    「Microsoft Edge」に76件もの脆弱性、修正版のv148.0.3967.70が安定チャネルに - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2109299.html Edge 固有の脆弱性 CVE-2026-45495 はハッキングコンテスト Pwn2Own で報告されたもの https://www.zerodayinitiative.com/advisories/ZDI-26-331/

    Post summary

    The article announces Microsoft Edge's patched release for 76 vulnerabilities, including CVE‑2026‑45495 reported at the Pwn2Own hacking contest, and links to a ZeroDay Initiative advisory.

    11010247
    544 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Microsoft Edge (Chromium-based) Remote Code Execution (CVE-2026-45495) A critical remote code execution (RCE) vulnerability exists in Microsoft Edge (Chromium-based). The flaw is caused by improper input validation (CWE-20) within the browser's rendering pipeline and JavaScript engine. An unauthenticated attacker can exploit this remotely by enticing a user to visit a maliciously crafted webpage, leading to memory corruption (such as a buffer overflow) and allowing the attacker to execute arbitrary code with the privileges of the Edge browser process. 👉 Affected: Microsoft Edge prior to version 148.0.3967.70 | Upgrade to 148.0.3967.70 or

    Post summary

    Microsoft announces a high‑severity remote code execution flaw (CVE‑2026‑45495) in Edge (Chromium), detailing its exploit vector and recommending a patch by upgrading to version 148.0.3967.70.

    00030233
    255 followersView on X
  • Proof of Patch@proofofpatch
    Disclosure

    Microsoft has disclosed three new vulnerabilities in Edge from the recent Pwn2Own contest, including CVE-2026-45495 which allows remote code execution via directory traversal in feedback log handling. These were demonstrated live at the event on June 4. Stay vigilant.

    Post summary

    Microsoft disclosed CVE-2026-45495, a remote code execution flaw in Edge due to directory traversal in feedback log handling, demonstrated live at Pwn2Own but without reference to exploitation, PoC, or patch details.

    0002082
    298 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45247 2 - CVE-2026-27914 3 - CVE-2017-11882 4 - CVE-2026-45495 5 - CVE-2026-0826 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists trending CVE identifiers without providing any additional details, evidence of exploitation, or actionable information.

    0002099
    1.7K followersView on X
  • Maxprotect@Maxprotectsoc
    General

    The real danger here isn't just the RCE (CVE-2026-45495) in isolation, it's the exploit chain. Combining a weak origin validation flaw with cross-origin script injection creates the perfect runway to bypass the browser sandbox entirely. It perfectly illustrates how smaller, individual logic bugs stack together to create a critical, zero-click compromise.

    Post summary

    The tweet explains how CVE‑2026‑45495’s remote code execution can be chained with weak origin validation and cross‑origin script injection to bypass the browser sandbox in a zero‑click scenario. This underscores the danger of small logic bugs stacking into a critical compromise.

    00020184
    32 followersView on X
  • kawn@kawn2020
    Disclosure

    #microsoftupdate #securityupdate #Edge 2026. 5.21 Microsoft Edge (Chromium ベース) のリモートでコードが実行される脆弱性 CVE-2026-45495 リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495

    Post summary

    The post announces the disclosure of CVE-2026-45495 as a remote code execution flaw in Microsoft Edge, without providing any exploit details, PoC, or patch information.

    10100141
    85 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    New advisory to triage: CVE-2026-45495. Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Inventory first. Panic never helps.

    Post summary

    The advisory identifies CVE-2026-45495 as a Remote Code Execution issue in Microsoft Edge but offers no further technical or operational details.

    1000041
    340 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft Edge の脆弱性 CVE-2026-45495 が FIX:任意のコード実行の可能性 https://iototsecnews.jp/2026/06/05/microsoft-edge-vulnerability-allows-remote-attackers-to-execute-arbitrary-code/ Microsoft Edge の脆弱性 CVE-2026-45495 は、ブラウザにおけるファイルパスの不適切な検証に起因します。この確認の不備を突く攻撃者が用意した不正なパスを、そのまま受け入れてしまい、意図しない場所へのファイル操作やプログラムの実行が引き起こされます。ユーザーの操作をきっかけとして、ログイン権限でコードが実行されるため、データの安全性が脅かされるリスクが生じます。ご利用のチームは、ご注意ください。 #CVE202645495 #Edge #Microsoft #Vulnerability

    Post summary

    The article reports that Microsoft Edge CVE-2026-45495, caused by inadequate file path validation, permits arbitrary code execution, but provides no PoC, exploit, or patch information.

    01000160
    499 followersView on X
  • ThreadLinqs@threadlinqs
    Patch

    THREAT INTEL: MS Edge CVE-2026-45495 - feedback-log path traversal = arbitrary file write, chainable to RCE. Patch Edge 148.0.3967.70. https://intel.threadlinqs.com/threat/TL-2026-0703 #ThreatIntel https://t.co/EYBIHsNkbC

    Post summary

    MS Edge CVE‑2026‑45495 is a path‑traversal flaw that permits arbitrary file writes and can be chained to RCE; Microsoft released patch 148.0.3967.70.

    0000048
    57 followersView on X
  • ThreadLinqs@threadlinqs
    Disclosure

    nNEW THREAT INTEL: Edge Path-Validation RCE CVE-2026-45495 - feedback-log directory traversal to code exec. PoC public, CVSS 7.5. https://intel.threadlinqs.com/threat/TL-2026-0703 #ThreatIntel #RCE https://t.co/rN5eFDam3n

    Post summary

    The tweet announces a newly discovered Edge Path‑Validation RCE (CVE‑2026‑45495) with known PoC and technical details, but no active exploitation, patch, or false‑positive claim is mentioned.

    0000065
    57 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-45495 Microsoft Edge(Chromiumベース)の脆弱性について https://www.cybernote.click/2026/05/30/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-45495-%ef%bc%88%e8%a3%bd%e5%93%81%e5%90%8d%e3%83%bb%e3%83%90%e3%83%bc%e3%82%b8%e3%83%a7%e3%83%b3%ef%bc%89%e3%81%ae%e8%84%86/ #IT #Security #cybersecurity

    Post summary

    The text merely signals that CVE‑2026‑45495 exists for Microsoft Edge, offering no technical depth, PoC, exploit, or remediation information.

    0000047
    209 followersView on X
  • kawn@kawn2020
    Disclosure

    #microsoftupdate #securityupdate #Edge CVE-2026-45495 影響: リモートでコードが実行される 最大深刻度: 重要 CVSS:3.1 8.8 / 7.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 悪用される可能性が高い https://x.com/kawn2020/status/2058768961735717064

    Post summary

    The tweet announces a new Microsoft Edge vulnerability (CVE‑2026‑45495) enabling remote code execution, with severity and CVSS scores provided, but no proof of concept, exploit, patch, or active exploitation details.

    0000073
    85 followersView on X
  • cybersecuritypath@cybrsecpath
    General

    Microsoft Edge RCE Flaw CVE-2026-45495 Puts Millions at Risk https://thecybrdef.com/microsoft-edge-rce-flaw-cve-2026-45495-puts-millions-at-risk/ #Cybertrending #Cybernewsdaily #Cybersecurity

    Post summary

    The supplied text mentions the existence of a CVE for Microsoft Edge but provides no technical details, PoC, exploit, or mitigation information.

    0000050
    9 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Microsoft Edge (CVE-2026-45495) https://vuldb.com/vuln/364484

    Post summary

    A brief note indicates the severity of a new Microsoft Edge vulnerability (CVE-2026-45495) has increased, but no further technical or exploit information is provided.

    0000079
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftedge_chromium---

Explore more