Threat reportVulnerabilityTL-2026-1505
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability (CVE-2026-58525)
Microsoft Edge (Chromium-based) Security Feature Bypass (TL-2026-1505) is a high-severity software vulnerability scored CVSS 8.2, first published 2026-07-08. It has no confirmed attribution, affects Microsoft Microsoft Edge (Chromium-based), references 1 CVE (CVE-2026-58525), maps to 12 MITRE ATT&CK techniques (T1005, T1189, T1204), and is covered by 9 detection rules and 21 indicators of compromise.
- CVSS
- 8.2/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1505
- Threat ID
- TL-2026-1505
- Severity
- HIGH
- CVSS
- 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, enterprise, finance, health, technology, all-browser-users
- Target regions
- hong kong, Global
- Detection rules
- 9
- Indicators of compromise
- 21
How Microsoft Edge (Chromium-based) Security Feature Bypass works
CVE-2026-58525 is a CVSS 8.2 improper-access-control flaw (CWE-284) in Microsoft Edge (Chromium-based) prior to version 150.0.4078.50 that lets a remote, unauthenticated attacker bypass a browser security restriction if a user is enticed to open a specially crafted web page. No public PoC and no active exploitation are reported; Microsoft rates it 'Important' with Exploit Code Maturity Unknown (E:U), and CISA SSVC rates exploitation as 'none' and technical impact as 'partial'.
CVE-2026-58525 was disclosed by Microsoft on July 8, 2026 as part of the July 2026 Patch Tuesday release, which the Zero Day Initiative's monthly review characterized as an unusually large cycle — ZDI's published review states the month shipped 621 CVEs in total, of which a large cluster (reported elsewhere as roughly 480) were Chromium-related, calling it a 'Mother of All Releases.' The flaw is classified as CWE-284 (Improper Access Control) in the Chromium-based build of Microsoft Edge and carries a CVSS 3.1 base score of 8.2 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C, temporal ~7.1); NVD has not yet published a CVSS v4.0 assessment for this CVE. The attack path requires no authentication and no special privileges, but does require user interaction: an attacker hosts a specially crafted web page and must entice a target to open it, typically via a phishing email, instant-message lure, or a malicious attachment/link sent through email — this enticement-via-attachment vector is explicitly called out in Microsoft's own description of the attack path. Once the page is loaded, the improper access-control logic allows the attacker to circumvent an expected browser security restriction, changing the scope of impact (S:C) and yielding high confidentiality impact (C:H) with limited integrity impact (I:L) and no availability impact (A:N) — consistent with a security-boundary bypass that exposes browser-protected data or state (e.g., session/origin-isolation data) rather than granting code execution or denial of service. Microsoft's own exploitability metrics record E:U (exploit code maturity unknown), RL:O (official fix available), and RC:C (report confidence confirmed); CISA's SSVC scoring for the CVE records exploitation status as 'none,' automatable as 'no,' and technical impact as 'partial.' Neither Microsoft, GovCERT.HK, nor the Zero Day Initiative's July 2026 review report any public proof-of-concept or in-the-wild exploitation as of publication, and the CVE is absent from the CISA Known Exploited Vulnerabilities (KEV) catalog as of 2026-07-19. Microsoft fixed the issue in Edge Stable 150.0.4078.50 (released July 8, 2026 across Windows, macOS, and other supported channels), and GovCERT.HK issued Security Alert A26-07-16 the following day urging Hong Kong organizations to update. The July 2026 Patch Tuesday cycle also shipped two closely related Edge (Chromium-based) Security Feature Bypass vulnerabilities — CVE-2026-57983 (CVSS 8.7) and CVE-2026-58295 (CVSS 8.3) — plus a lower-severity companion, CVE-2026-58523, affecting Microsoft Edge for Android (CVSS 6.5), indicating a cluster of access-control hardening fixes shipped to the Edge/Chromium codebase in the same release rather than an isolated one-off defect. NVD's record and third-party trackers (thewindowsupdate.com, datacomm.com, cve.threatint) mirror MSRC's advisory text verbatim, with no independent technical write-up, exploit chain analysis, or PoC code published by any tracked source, reflecting the genuinely thin public documentation typical of this CVE class before independent researchers reverse-engineer the patch diff.
MITRE ATT&CK techniques used in TL-2026-1505
Collection
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Execution
Defense Evasion
T1211 Exploitation for Stealth
Discovery
T1217 Browser Information Discovery
Credential Access
T1539 Steal Web Session Cookie
privilege-escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
Reconnaissance
T1594 Search Victim-Owned Websites
defense-impairment
Affected products and versions in Microsoft Edge (Chromium-based) Security Feature Bypass
- Microsoft — Microsoft Edge (Chromium-based)
Vulnerable versions: < 150.0.4078.50
Fixed in: 150.0.4078.50
Remediation for Microsoft Edge (Chromium-based) Security Feature Bypass
Patches
- Microsoft Edge (Chromium-based) Stable 150.0.4078.50 (released 2026-07-08) resolves CVE-2026-58525.
Immediate actions
- Update Microsoft Edge (Chromium-based) to version 150.0.4078.50 or later on all Windows, macOS, and managed endpoints.
- Push the Edge security update via enterprise patch/update management (Microsoft Intune, WSUS, Configuration Manager, or the Edge auto-update channel) rather than waiting for opportunistic user-driven updates.
- Verify current Edge version fleet-wide via managed browser telemetry to confirm no endpoints remain below 150.0.4078.50.
Workarounds
- No official workaround is published; updating to the fixed build is the only remediation documented by Microsoft/GovCERT.HK.
Longer-term hardening
- Enforce Edge auto-update policies and block user ability to defer or disable browser updates on managed devices.
- Maintain browser patch-compliance monitoring as part of standard vulnerability management given the recurring cadence of Edge/Chromium Security Feature Bypass CVEs (this release alone shipped three: CVE-2026-58525, CVE-2026-57983, CVE-2026-58295).
- Layer web/email gateway filtering and user security-awareness training against enticement-based lures, since exploitation of this CVE class depends on convincing a user to open a crafted link or attachment.
- Continue monitoring CISA KEV and vendor advisories for this CVE cluster; SSVC currently rates exploitation 'none' and automatable 'no,' but that can change if a researcher publishes a patch-diff-derived PoC.
CVEs associated with Microsoft Edge (Chromium-based) Security Feature Bypass
CVE-2026-58525
Weaknesses (CWE) in Microsoft Edge (Chromium-based) Security Feature Bypass
Timeline of Microsoft Edge (Chromium-based) Security Feature Bypass
- Third-party trackers (thewindowsupdate.com, DataComm Networks, THREATINT) republish the MSRC advisory text for CVE-2026-58525 the same day, with no added technical detail.
- NVD publishes its own record for CVE-2026-58525 mirroring the MSRC CVSS 3.1 vector and CWE-284 classification; CVSS v4.0 not yet assessed.
- Microsoft Edge (Chromium-based) Stable version 150.0.4078.50, which fixes CVE-2026-58525, released for Windows and macOS.
- CVE-2026-58525 published by Microsoft via the MSRC Security Update Guide as part of July 2026 Patch Tuesday, rated CVSS 8.2 / Important.
- GovCERT.HK issues Security Alert A26-07-16 covering the Microsoft Edge vulnerability and recommending users update to the patched version.
- NVD record for CVE-2026-58525 last-modified; CISA SSVC scoring recorded for the CVE as exploitation 'none,' automatable 'no,' technical impact 'partial.'
- Zero Day Initiative publishes its July 2026 Security Update Review, listing CVE-2026-58525 among the month's 621 total CVEs (with roughly 480 characterized as Chromium-related) and describing the cycle as a 'Mother of All Releases,' with no known public exploitation reported for this CVE.
- TL-Intel Harness HUNT phase selects CVE-2026-58525 for deep-dive research after it cleared the CVSS >= 7.0 network-attack-vector selection threshold from the GovCERT.HK feed.
- CVE-2026-58525 confirmed absent from the CISA Known Exploited Vulnerabilities (KEV) catalog as of this date.
Sources cited for Microsoft Edge (Chromium-based) Security Feature Bypass
- GovCERT.HK Security Alert (A26-07-16): Vulnerability in Microsoft Edge
- Microsoft Security Update Guide - CVE-2026-58525
- NVD - CVE-2026-58525
- CVE-2026-58525 | THREATINT
- CVE-2026-58525 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- Zero Day Initiative — The July 2026 Security Update Review
- CVE-2026-58525 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability - DataComm Networks
- CVE-2026-58523: Microsoft Edge for Android Security Feature Bypass (CVSS 6.5)
- Release notes for Microsoft Edge Security Updates
Detection coverage for TL-2026-1505
As of 2026-07-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1505 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.