Threat reportVulnerabilityTL-2026-0703

Microsoft Edge CVE-2026-45495 — Feedback-Log Path-Validation Remote Code Execution

highACTIVE

Microsoft Edge CVE-2026-45495 (TL-2026-0703), also tracked as Edge Feedback-Log Path Traversal RCE, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-06-07. It has no confirmed attribution, affects Microsoft Microsoft Edge (Chromium-based), references 1 CVE (CVE-2026-45495), maps to 11 MITRE ATT&CK techniques (T1005, T1021, T1189), and is covered by 9 detection rules and 12 indicators of compromise.

CVSS
7.5/10High
CVEs
1Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-0703

Threat ID
TL-2026-0703
Also known as
Edge Feedback-Log Path Traversal RCE
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, technology, healthcare, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
12

How Microsoft Edge CVE-2026-45495 works

CVE-2026-45495 is a HIGH-severity (CVSS 7.5) directory-traversal flaw in the feedback-log file handling of Chromium-based Microsoft Edge. Edge fails to validate a user-supplied file path before performing file operations, letting a remote attacker who lures a user to a crafted page or file write to attacker-chosen locations and, chained with other bugs, achieve arbitrary code execution in the logged-in user's context. Reported by Orange Tsai of DEVCORE; patched in Edge 148.0.3967.70. No confirmed in-the-wild exploitation or public PoC as of the 2026-06-04 advisory.

CVE-2026-45495 is a path-validation (directory/path traversal, CWE-35 / CWE-20) vulnerability in the feedback-log file-handling component of Chromium-based Microsoft Edge, disclosed in Microsoft's coordinated Edge security release of 2026-06-04 and credited to Orange Tsai of DEVCORE.

ROOT CAUSE: When Edge processes feedback-log files it accepts a user-influenceable file path and performs file operations (read/write) on that path without sufficiently validating or canonicalizing it. Because traversal sequences (e.g., ../ or absolute paths) are not stripped or rejected before the path reaches the file API, an attacker who can influence the supplied path can direct Edge's privileged-within-user-context file operations to locations outside the intended feedback/log directory.

EXPLOIT CHAIN: The vulnerability is not directly wormable — it requires user interaction. The documented initial-access vector is social engineering: luring the victim to a crafted web page, or convincing them to open a malicious file or download. Once the path-validation defect is triggered, the attacker controls where a file write lands. By itself this is an arbitrary-file-write / path-traversal primitive; chained with a complementary bug (or by writing to an auto-executed location such as a user Startup folder or a DLL search path consumed by a user-context process), it is escalated to arbitrary code execution. All execution occurs with the privileges of the signed-in user — there is no built-in privilege escalation. Consequent impact ranges from browser-profile and credential/cookie theft, to local persistence, to lateral movement where the compromised account holds elevated rights.

IMPACT CONTEXT: Edge is broadly deployed across enterprise endpoints and is the default browser on managed Windows fleets, so a reliable lure plus a chaining bug yields a wide soft attack surface. Microsoft rated the flaw HIGH with a CVSS v3 base score of 7.5 (high attack complexity offset by network vector and full CIA impact). Some third-party aggregators list inflated scores (8.8 / 9.0) derived from differing vector assumptions; the vendor and the majority of sources align on 7.5.

RELATED FIXES: The same Edge security release addressed CVE-2026-45494 (CVSS 5.0, cross-origin script injection in navigation handling) and CVE-2026-45492 (CVSS 4.3, insufficient origin validation in cross-device sign-in). CVE-2026-45495 is the most severe of the set.

REMEDIATION: Update to Microsoft Edge 148.0.3967.70 or later. Edge auto-updates for most consumers, but managed/air-gapped fleets and pinned-version deployments require explicit action. Defenders should hunt for msedge.exe (or its renderer/utility children) performing file writes outside the expected Edge User Data directory, especially to auto-run locations.

MITRE ATT&CK techniques used in TL-2026-0703

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Execution

T1203 Exploitation for Client Execution; T1204 User Execution

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Persistence

T1547 Boot or Logon Autostart Execution

privilege-escalation

T1548 Abuse Elevation Control Mechanism

stealth

T1574 Hijack Execution Flow

Affected products and versions in Microsoft Edge CVE-2026-45495

  • Microsoft — Microsoft Edge (Chromium-based)
    Vulnerable versions: < 148.0.3967.70
    Fixed in: 148.0.3967.70

Remediation for Microsoft Edge CVE-2026-45495

Patches

  • Microsoft Edge 148.0.3967.70 (Stable channel, desktop) and later

Immediate actions

  • Update Microsoft Edge to 148.0.3967.70 or later via edge://settings/help (About page) or Microsoft Update
  • Verify managed/pinned-version fleets are not held below 148.0.3967.70 by update policy
  • Caution users against opening unsolicited files/links and exporting/opening Edge feedback logs from untrusted sources

Workarounds

  • Where patching is delayed, restrict opening of untrusted feedback-log / downloaded files and apply application allowlisting on user auto-run locations (Startup folders, per-user Run keys)

Longer-term hardening

  • Enforce least-privilege accounts so user-context code execution does not yield elevated rights
  • Deploy EDR rules flagging browser processes writing outside their profile/User Data directory
  • Adopt automated browser-update enforcement to eliminate version pinning drift

CVEs associated with Microsoft Edge CVE-2026-45495

CVE-2026-45495

Weaknesses (CWE) in Microsoft Edge CVE-2026-45495

CWE-35, CWE-20

Timeline of Microsoft Edge CVE-2026-45495

  • Microsoft initially lists CVE-2026-45495 in the Security Update Guide as a high-severity Chromium-based Edge remote code execution vulnerability.
  • Vulnerability reported to Microsoft; credited to Orange Tsai of DEVCORE.
  • MSRC entry updated (CWE classification added — informational change).
  • Microsoft Edge 148.0.3967.70 published to the Stable desktop channel, remediating the feedback-log path-validation flaw.
  • Coordinated public advisories released/updated by Microsoft and Rapid7; fix shipped in Edge 148.0.3967.70.
  • Threadlinqs Intelligence documents the threat; no confirmed in-the-wild exploitation or public PoC observed at time of analysis.

Sources cited for Microsoft Edge CVE-2026-45495

Detection coverage for TL-2026-0703

As of 2026-06-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0703 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats