Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5589 articles · 220728 vulns · 37/41 feeds (7d)
← Back to list
4.2
CVE-2026-55945EXPLOITEDPATCHED
microsoft · edge_chromium

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

Affected Products

VendorProductVersions
microsoftedge_chromium1.0.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftedgecert_advisory90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55945(vendor-advisory, patch)

Related News (6 articles)

Tier D
BleepingComputer2d ago
BragJack attacks hijack AI browser agents through malicious extensions
→ No new info (linked only)
Tier D
Dark Reading5d ago
BragJack Attack Can Turn a Browser's Agentic AI Against It
→ No new info (linked only)
Tier D
The Hacker News5d ago
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
→ No new info (linked only)
Tier B
BSI Advisories78d ago
[NEU] [hoch] Microsoft Edge: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB80d ago
CVE-2026-55945 | Microsoft Edge up to 149.0.4022.68 race condition
→ No new info (linked only)
Tier A
Microsoft MSRC80d ago
CVE-2026-55945 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.14.2 MEDIUM
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
150.0.4078.48
CWECWE-362
PublishedJul 3, 2026
Last enriched80d agov3
Trending Score44
Source articles6
Independent6
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85880EXPKEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Trending: 55
HIGHCVE-2026-66804
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Trending: 49
CRITICALCVE-2026-70352
Azure AI Language Elevation of Privilege Vulnerability
Trending: 44
HIGHCVE-2026-88097
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Trending: 43
CRITICALCVE-2026-62916
Microsoft Entra ID Elevation of Privilege Vulnerability
Trending: 41

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 3, 2026
Discovered by ZDM
Jul 3, 2026
Updated: description, exploitAvailable, activelyExploited
Jul 3, 2026
Updated: affectedVersions
Jul 4, 2026
Actively Exploited
Sep 8, 2026
Exploit Available
Sep 8, 2026
Patch Available
Sep 8, 2026

Version History

v3
Last enriched 80d ago
v3Tier C80d ago

Updated affected versions to include 149.0.4022.68 and changed severity from MEDIUM to HIGH.

affectedVersions
via VulDB
v2Tier A80d ago

Added a detailed description of the vulnerability and marked it as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v180d ago

Initial creation