CVE-2026-55945
published 2026-07-03CVE-2026-55945: Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to…
PriorityP419medium4.2CVSS 3.1
AVLACHPRLUINSCCLILAN
EPSS
0.14%
4.2th percentile
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 150.0.4078.48 | 150.0.4078.48 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 150.0.4078.48 | 150.0.4078.48 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Edge up to 149.0.4022.68 race condition (EUVD-2026-41645 / WID-SEC-2026-2200)
vuldb·2026-07-12·CVSS 4.2
CVE-2026-55945 [MEDIUM] Microsoft Edge up to 149.0.4022.68 race condition (EUVD-2026-41645 / WID-SEC-2026-2200)
A vulnerability, which was classified as problematic, was found in Microsoft Edge. Affected is an unknown function. Executing a manipulation can lead to race condition.
This vulnerability is registered as CVE-2026-55945. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.
GHSA
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
ghsa_unreviewed·2026-07-03
CVE-2026-55945 [MEDIUM] CWE-362 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
No detection rules found.
No public exploits indexed.
2026-07-03
Published