
[CIVN-2026-0013] Security Restriction Bypass Vulnerability in Microsoft Edge (Chromium-based)
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Security Restriction Bypass Vulnerability in Microsoft Edge (Chromium-based)
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Microsoft Edge (Chromium-based) version prior to 143.0.3650.139
Overview
A vulnerability has been reported in Microsoft Edge (Chromium-based) which could allow a remote attacker to bypass security restrictions on the targeted system.
Target Audience:
All end-user organizations and individuals using Microsoft Edge.
Risk Assessment:
High risk of Security boundary bypass enabling unauthorized access and potential data theft.
Impact Assessment:
Potential for security restriction bypass or sensitive data disclosure.
Description
Microsoft Edge is a web browser developed by Microsoft using the Chromium engine, offering fast performance, enhanced security, and compatibility with modern web standards while integrating with Microsoft services.
This vulnerability exists in Microsoft Edge (Chromium-based) due to Insufficient policy enforcement in WebView tag. A remote attacker could exploit this vulnerability by persuading a victim to visit a specially crafted webpage.
Successful exploitation of this vulnerability could allow a remote attacker to bypass security restrictions on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#january-9-2026
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0628
References
Microsoft
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0628
CVE Name
CVE-2026-0628
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmllCkgACgkQ3jCgcSdc
ys8ajw/+MDEdhIbwxGC3tcCO2DhxPoTuNoOR7O0nQAs3hZEQ1kEMF4FAnalYFcBa
ojkNLucja1c0Ns8NEfQLgIIf98fTMfQF64ohsptJUBf7GafNv221CkqhoQjoA4ks
m5RiELD92N00wSqQ3F3Uq2omi7ydRio6fUka3LBNUJeVxibsfH3Bd+K7vnLfjPIF
sgHGj6MPRmbzKLjHxnNtkNT151tjVphkT5HVBQZPNM9RgWkde7bp5gr/2r783PRd
eEdyKkxcz3CDCjMD8YCZWayh7soXPQdx+tIVp/6rhUtbUftLCuX8dgpabg7mjffV
ywDxpjE3hqPNKA2FE8aEKN7dyg8ksrmhw1VhYJBWceRzCCbmSjON9MYHiHYhe8CP
sBkEisqgiZMhvixBrCGsu9RXG1zo5K76Jg4HrI4Rk3c6e3joI2GVwO/wC351TWqx
o0spoz9ix5TPdCxlqc6xHMaC1C0g+SQfJE4DkiQ8O1WtLC3zFhvj7IimEP+ozrAz
Iu3nc9coL+EdC+KTDbEM+ltsSSBxwta+9YXxJats78Eo81Y/caLW+ciaeZvghcS/
NaW8oz5HLwf2M81IMCiuFavqQU7Rswz+KzU21kuY2l7oXsZVxJY1yZeV+cg+jOnG
cb0u/YUwEq/+i0WKIV9xWxlbXZzix8HqmS7wxJQrbA99yoEi58A=
=PNGo
—–END PGP SIGNATURE—–


