VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Edge security bypass flaw patched

low vulnerability

A vulnerability in Microsoft Edge versions before 150.0.4078.50 allows an attacker to bypass security policy protections.

ANSSI-FR (CERT-FR) issued an advisory regarding a security policy bypass vulnerability affecting Microsoft Edge versions prior to 150.0.4078.50. The flaw, tracked as CVE-2026-58525, was disclosed via Microsoft's security bulletin on 8 July 2026 and could allow an attacker to circumvent intended security policy controls within the browser.

No evidence of active exploitation is mentioned in the advisory, and no proof-of-concept or in-the-wild attack details are provided. Users and administrators are advised to apply the vendor-supplied patch referenced in Microsoft's official update guide to remediate the issue.

Mentioned in this report

Vulnerabilities CVE-2026-58525

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0854

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free