Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-41107

Опубликовано: 11 мая 2026
Источник: msrc
CVSS3: 7.4
EPSS Низкий

Описание

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability?

The type of information that could be disclosed if an attacker successfully exploited this vulnerability by bypassing a security feature that is built in to prevent cookies from being read is cookies data and cached sessions. By reading a session cookie, an attacker would be able to sign into the victim’s accounts on a different computer.

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

An attacker must send a user a malicious Office file and convince them to open it.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

This vulnerability could lead to a browser sandbox escape.

What is the version information for this release?

Microsoft Edge VersionDate ReleasedBased on Chromium Version
148.0.3967.5505/11/2026148.0.7778.97

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 48%
0.00652
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
3 месяца назад

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
github
3 месяца назад

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVSS3: 7.4
fstec
3 месяца назад

Уязвимость браузера Microsoft Edge, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 48%
0.00652
Низкий

7.4 High

CVSS3