Threat reportVulnerabilityTL-2026-0703
Microsoft Edge CVE-2026-45495 — Feedback-Log Path-Validation Remote Code Execution
Microsoft Edge CVE-2026-45495 (TL-2026-0703), also tracked as Edge Feedback-Log Path Traversal RCE, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-06-07. It has no confirmed attribution, affects Microsoft Microsoft Edge (Chromium-based), references 1 CVE (CVE-2026-45495), maps to 11 MITRE ATT&CK techniques (T1005, T1021, T1189), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-0703
- Threat ID
- TL-2026-0703
- Also known as
- Edge Feedback-Log Path Traversal RCE
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, technology, healthcare, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
How Microsoft Edge CVE-2026-45495 works
CVE-2026-45495 is a HIGH-severity (CVSS 7.5) directory-traversal flaw in the feedback-log file handling of Chromium-based Microsoft Edge. Edge fails to validate a user-supplied file path before performing file operations, letting a remote attacker who lures a user to a crafted page or file write to attacker-chosen locations and, chained with other bugs, achieve arbitrary code execution in the logged-in user's context. Reported by Orange Tsai of DEVCORE; patched in Edge 148.0.3967.70. No confirmed in-the-wild exploitation or public PoC as of the 2026-06-04 advisory.
CVE-2026-45495 is a path-validation (directory/path traversal, CWE-35 / CWE-20) vulnerability in the feedback-log file-handling component of Chromium-based Microsoft Edge, disclosed in Microsoft's coordinated Edge security release of 2026-06-04 and credited to Orange Tsai of DEVCORE.
ROOT CAUSE: When Edge processes feedback-log files it accepts a user-influenceable file path and performs file operations (read/write) on that path without sufficiently validating or canonicalizing it. Because traversal sequences (e.g., ../ or absolute paths) are not stripped or rejected before the path reaches the file API, an attacker who can influence the supplied path can direct Edge's privileged-within-user-context file operations to locations outside the intended feedback/log directory.
EXPLOIT CHAIN: The vulnerability is not directly wormable — it requires user interaction. The documented initial-access vector is social engineering: luring the victim to a crafted web page, or convincing them to open a malicious file or download. Once the path-validation defect is triggered, the attacker controls where a file write lands. By itself this is an arbitrary-file-write / path-traversal primitive; chained with a complementary bug (or by writing to an auto-executed location such as a user Startup folder or a DLL search path consumed by a user-context process), it is escalated to arbitrary code execution. All execution occurs with the privileges of the signed-in user — there is no built-in privilege escalation. Consequent impact ranges from browser-profile and credential/cookie theft, to local persistence, to lateral movement where the compromised account holds elevated rights.
IMPACT CONTEXT: Edge is broadly deployed across enterprise endpoints and is the default browser on managed Windows fleets, so a reliable lure plus a chaining bug yields a wide soft attack surface. Microsoft rated the flaw HIGH with a CVSS v3 base score of 7.5 (high attack complexity offset by network vector and full CIA impact). Some third-party aggregators list inflated scores (8.8 / 9.0) derived from differing vector assumptions; the vendor and the majority of sources align on 7.5.
RELATED FIXES: The same Edge security release addressed CVE-2026-45494 (CVSS 5.0, cross-origin script injection in navigation handling) and CVE-2026-45492 (CVSS 4.3, insufficient origin validation in cross-device sign-in). CVE-2026-45495 is the most severe of the set.
REMEDIATION: Update to Microsoft Edge 148.0.3967.70 or later. Edge auto-updates for most consumers, but managed/air-gapped fleets and pinned-version deployments require explicit action. Defenders should hunt for msedge.exe (or its renderer/utility children) performing file writes outside the expected Edge User Data directory, especially to auto-run locations.
MITRE ATT&CK techniques used in TL-2026-0703
Collection
Lateral Movement
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Execution
T1203 Exploitation for Client Execution; T1204 User Execution
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Persistence
T1547 Boot or Logon Autostart Execution
privilege-escalation
T1548 Abuse Elevation Control Mechanism
stealth
Affected products and versions in Microsoft Edge CVE-2026-45495
- Microsoft — Microsoft Edge (Chromium-based)
Vulnerable versions: < 148.0.3967.70
Fixed in: 148.0.3967.70
Remediation for Microsoft Edge CVE-2026-45495
Patches
- Microsoft Edge 148.0.3967.70 (Stable channel, desktop) and later
Immediate actions
- Update Microsoft Edge to 148.0.3967.70 or later via edge://settings/help (About page) or Microsoft Update
- Verify managed/pinned-version fleets are not held below 148.0.3967.70 by update policy
- Caution users against opening unsolicited files/links and exporting/opening Edge feedback logs from untrusted sources
Workarounds
- Where patching is delayed, restrict opening of untrusted feedback-log / downloaded files and apply application allowlisting on user auto-run locations (Startup folders, per-user Run keys)
Longer-term hardening
- Enforce least-privilege accounts so user-context code execution does not yield elevated rights
- Deploy EDR rules flagging browser processes writing outside their profile/User Data directory
- Adopt automated browser-update enforcement to eliminate version pinning drift
CVEs associated with Microsoft Edge CVE-2026-45495
Weaknesses (CWE) in Microsoft Edge CVE-2026-45495
Timeline of Microsoft Edge CVE-2026-45495
- Microsoft initially lists CVE-2026-45495 in the Security Update Guide as a high-severity Chromium-based Edge remote code execution vulnerability.
- Vulnerability reported to Microsoft; credited to Orange Tsai of DEVCORE.
- MSRC entry updated (CWE classification added — informational change).
- Microsoft Edge 148.0.3967.70 published to the Stable desktop channel, remediating the feedback-log path-validation flaw.
- Coordinated public advisories released/updated by Microsoft and Rapid7; fix shipped in Edge 148.0.3967.70.
- Threadlinqs Intelligence documents the threat; no confirmed in-the-wild exploitation or public PoC observed at time of analysis.
Sources cited for Microsoft Edge CVE-2026-45495
- Rapid7 — Microsoft Edge CVE-2026-45495
- Microsoft Edge Security Update Release Notes
- Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code
- CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — MSRC
- CVE-2026-45495 — Vulnerability Details — OpenCVE
- Microsoft Edge Vulnerability Enables Remote Code Execution — Cyberpress
Detection coverage for TL-2026-0703
As of 2026-06-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0703 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.