• PATCH AVAILABLE

CVE-2026-57983: pre-auth authorization bypass in Microsoft Microsoft Edge (Chromium-based)

An unauthenticated remote attacker can bypass a security feature in Microsoft Edge (Chromium-based), allowing unauthorized actions against the browser. This is tracked as CVE-2026-57983. The issue affects Microsoft Edge 150.x versions from 1.0.0.0 up to, but not including, 150.0.4078.48; the vendor lists a fixed build of 150.0.4078.48. Exploitation requires only network access and no valid user credentials or interaction, per the vendor description and the CVSS vector values.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00648
CWE
CWE-285
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a critical, network-accessible bypass that requires no authentication; update Microsoft Edge to build 150.0.4078.48 immediately where possible.

What is CVE-2026-57983?

An unauthenticated remote attacker can bypass a security feature in Microsoft Edge (Chromium-based), allowing unauthorized actions against the browser. This is tracked as CVE-2026-57983. The issue affects Microsoft Edge 150.x versions from 1.0.0.0 up to, but not including, 150.0.4078.48; the vendor lists a fixed build of 150.0.4078.48. Exploitation requires only network access and no valid user credentials or interaction, per the vendor description and the CVSS vector values.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Microsoft Microsoft Edge (Chromium-based) are affected?

BRANCHAFFECTEDFIXED
150.x1.0.0.0 – before 150.0.4078.48150.0.4078.48

Is CVE-2026-57983 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-57983

  1. Update Microsoft Edge to the fixed release 150.0.4078.48.
  2. If you cannot update immediately, restrict network exposure of affected endpoints and block untrusted network sources.
  3. Apply vendor guidance and enterprise update policies to roll out the fixed build to all managed devices.
  4. Monitor browser logs and network telemetry for unusual or unauthorized activity related to Edge processes.

Frequently asked questions

Is CVE-2026-57983 being actively exploited?

There are no public reports of exploitation of CVE-2026-57983 as of 2026-09-29.

Which Microsoft Edge versions are affected by CVE-2026-57983?

Microsoft Edge (Chromium-based) branch 150.x versions from 1.0.0.0 up to, but not including, 150.0.4078.48 are affected.

Is there a patch for CVE-2026-57983?

Yes. Microsoft lists a fixed build: 150.0.4078.48.

Does CVE-2026-57983 require authentication?

No. The vulnerability allows an unauthenticated attacker with network access to bypass a security feature without valid credentials or user interaction.

References