CVE-2026-66312
published 2026-08-04CVE-2026-66312: Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
PriorityP258high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.57%
45.1th percentile
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 151.0.4129.59 | 151.0.4129.59 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 151.0.4129.59 | 151.0.4129.59 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Edge up to 150.0.4078.99 buffer over-read
vuldb·2026-08-04·CVSS 6.5
CVE-2026-66312 [MEDIUM] Microsoft Edge up to 150.0.4078.99 buffer over-read
A vulnerability was found in Microsoft Edge. It has been declared as critical. Impacted is an unknown function. Executing a manipulation can lead to buffer over-read.
This vulnerability is registered as CVE-2026-66312. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
ghsa_unreviewed·2026-08-04
CVE-2026-66312 [MEDIUM] CWE-126 Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-04
Published