# Microsoft Edge CVE-2026-45495 — Feedback-Log Path-Validation Remote Code Execution

> CVE-2026-45495 is a HIGH-severity (CVSS 7.5) directory-traversal flaw in the feedback-log file handling of Chromium-based Microsoft Edge. Edge fails to validate a user-supplied file path before performing file operations, letting a remote attacker who lures a user to a crafted page or file write to attacker-chosen locations and, chained with other bugs, achieve arbitrary code execution in the logged-in user's context. Reported by Orange Tsai of DEVCORE; patched in Edge 148.0.3967.70. No confirmed in-the-wild exploitation or public PoC as of the 2026-06-04 advisory.

- **Published:** 2026-06-07T00:00:00Z
- **Last reviewed:** 2026-06-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0703
- **ID:** TL-2026-0703
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45495

## Description

CVE-2026-45495 is a path-validation (directory/path traversal, CWE-35 / CWE-20) vulnerability in the feedback-log file-handling component of Chromium-based Microsoft Edge, disclosed in Microsoft's coordinated Edge security release of 2026-06-04 and credited to Orange Tsai of DEVCORE.

ROOT CAUSE: When Edge processes feedback-log files it accepts a user-influenceable file path and performs file operations (read/write) on that path without sufficiently validating or canonicalizing it. Because traversal sequences (e.g., ../ or absolute paths) are not stripped or rejected before the path reaches the file API, an attacker who can influence the supplied path can direct Edge's privileged-within-user-context file operations to locations outside the intended feedback/log directory.

EXPLOIT CHAIN: The vulnerability is not directly wormable — it requires user interaction. The documented initial-access vector is social engineering: luring the victim to a crafted web page, or convincing them to open a malicious file or download. Once the path-validation defect is triggered, the attacker controls where a file write lands. By itself this is an arbitrary-file-write / path-traversal primitive; chained with a complementary bug (or by writing to an auto-executed location such as a user Startup folder or a DLL search path consumed by a user-context process), it is escalated to arbitrary code execution. All execution occurs with the privileges of the signed-in user — there is no built-in privilege escalation. Consequent impact ranges from browser-profile and credential/cookie theft, to local persistence, to lateral movement where the compromised account holds elevated rights.

IMPACT CONTEXT: Edge is broadly deployed across enterprise endpoints and is the default browser on managed Windows fleets, so a reliable lure plus a chaining bug yields a wide soft attack surface. Microsoft rated the flaw HIGH with a CVSS v3 base score of 7.5 (high attack complexity offset by network vector and full CIA impact). Some third-party aggregators list inflated scores (8.8 / 9.0) derived from differing vector assumptions; the vendor and the majority of sources align on 7.5.

RELATED FIXES: The same Edge security release addressed CVE-2026-45494 (CVSS 5.0, cross-origin script injection in navigation handling) and CVE-2026-45492 (CVSS 4.3, insufficient origin validation in cross-device sign-in). CVE-2026-45495 is the most severe of the set.

REMEDIATION: Update to Microsoft Edge 148.0.3967.70 or later. Edge auto-updates for most consumers, but managed/air-gapped fleets and pinned-version deployments require explicit action. Defenders should hunt for msedge.exe (or its renderer/utility children) performing file writes outside the expected Edge User Data directory, especially to auto-run locations.

## MITRE ATT&CK

- T1189 Drive-by Compromise
- T1566 Phishing
- T1204 User Execution
- T1203 Exploitation for Client Execution
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1548 Abuse Elevation Control Mechanism
- T1539 Steal Web Session Cookie
- T1555 Credentials from Password Stores
- T1005 Data from Local System
- T1021 Remote Services

## Sources

- [Rapid7 — Microsoft Edge CVE-2026-45495](https://www.rapid7.com/db/vulnerabilities/microsoft-edge-cve-2026-45495/)
- [Microsoft Edge Security Update Release Notes](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security)
- [Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code](https://cybersecuritynews.com/microsoft-edge-vulnerability-code-execution/)
- [CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — MSRC](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45495)
- [CVE-2026-45495 — Vulnerability Details — OpenCVE](https://app.opencve.io/cve/CVE-2026-45495)
- [Microsoft Edge Vulnerability Enables Remote Code Execution — Cyberpress](https://cyberpress.org/microsoft-edge-vulnerability/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0703
