CVE-2026-41107: Microsoft Edge Chromium

High severity, CVSS 7.4. EPSS: 0.9% chance of exploitation in the next 30 days.

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Affected products

  • Microsoft Edge Chromium: before 148.0.3967.55 (fixed in 148.0.3967.55)

Published 2026-05-12. Last modified 2026-06-17.