Skip to content
MicrosoftCVE-2026-58281

Microsoft Edge (Chromium-based): unsafe deserialization

High8.3CVE-2026-58281 · Published Jul 11, 2026 · updated Jul 14, 2026

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Microsoft advisory

Affected versions

PackageAffectedFixed in
Microsoft Edge (Chromium-based)
Product
>= 1.0.0.0, < 150.0.4078.48150.0.4078.48
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-502

More Microsoft advisories

All Microsoft
Advisory
Microsoft Windows Media: information disclosure
Medium5.5Jul 14
Microsoft Windows Event Logging Service: protection mechanism failure
Medium6.5Jul 14
Microsoft Windows Ancillary Function Driver for WinSock: cleartext secrets
Medium5.5Jul 14
Microsoft Edge (Chromium-based): privilege escalation
High8.3Jul 12
Microsoft Dynamics 365 Customer Voice: cross-site scripting
Critical9.3Jul 9
Microsoft Edge (Chromium-based): improper access control
High8.2Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.