CVE-2026-58291: Edge Chromium Vulnerability (CVSS 6.1)

{ "cveId": "CVE-2026-58291", "severity": { "rating": "medium", "cvss": 6.1, "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N" }, "exploitationProbability": { "epss": 0.60, "percentile": "44.4th" }, "description": "Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.", "metrics": { "cvss": "CVSS 3.16.1/10" }, "weaknessEnumeration": [ "CWE-672" ], "affectedSoftware": [ { "vendor": "Microsoft", "product": "Edge Chromium", "versions": "< 150.0.4078.48" } ], "references": [ { "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58291", "description": "Vendor Advisory" } ], "timeline": { "published": "Jul 3, 2026", "lastModified": "Jul 6, 2026", "status": "Analyzed" }, "faqs": [ { "question": "What is CVE-2026-58291?", "answer": "Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network." }, { "question": "How severe is CVE-2026-58291?", "answer": "CVE-2026-58291 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.60% probability of exploitation in the next 30 days." }, { "question": "How do I fix CVE-2026-58291?", "answer": "Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected." } ], "relatedCVEs": [ { "cve": "CVE-2026-58286", "description": "Improper access control in Microsoft Edge (Chromium-based)", "severity": "6.9" }, { "cve": "CVE-2026-58287", "description": "Use after free in Microsoft Edge (Chromium-based)", "severity": "8.3" }, { "cve": "CVE-2026-58288", "description": "Use after free in Microsoft Edge (Chromium-based)", "severity": "8.3" }, { "cve": "CVE-2026-58289", "description": "Access of resource using incompatible type ('type confusion')", "severity": "8.3" }, { "cve": "CVE-2026-5829", "description": "A vulnerability was determined in code-projects Simple IT", "severity": "7.3" }, { "cve": "CVE-2026-58290", "description": "Access of resource using incompatible type ('type confusion')", "severity": "7.5" }, { "cve": "CVE-2026-58292", "description": "Improper input validation in Microsoft Edge (Chromium-based)", "severity": "7.5" }, { "cve": "CVE-2026-58293", "description": "External control of file name or path in Microsoft Edge (Chromium-based)", "severity": "7.5" }, { "cve": "CVE-2026-58294", "description": "Use after free in Microsoft Edge (Chromium-based)", "severity": "7.5" }, { "cve": "CVE-2026-58295", "description": "Access of resource using incompatible type ('type confusion')", "severity": "8.3" }, { "cve": "CVE-2026-58296", "description": "Exposure of private personal information to an unauthorized", "severity": "7.1" }, { "cve": "CVE-2026-58297", "description": "Exposure of private personal information to an unauthorized", "severity": "7.1" } ] }