← Vulnerability feed

Vulnerability record · CVE-2026-58281 · published 11 July 2026

CVE-2026-58281: Microsoft edge chromium deserialization of untrusted data vulnerability

Microsoft · Edge Chromium

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

8.3 CVSS 3.1 High EPSS 0.96% · top 40.1% CWE-502 · Deserialization of untrusted data
8.3CVSS 3.1 base score
0.96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
14 Jul 2026Last modified by NVD

Description

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-58281 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2023-6345Chrome Skia integer overflow enables sandbox escapeAn integer overflow in Skia in Google Chrome before 119.0.6045.199 lets a remote attacker who already controls the renderer process escape the browse…KEVEPSS 16%analysed9.6CVE-2022-4135Google Chrome GPU heap buffer overflow enables sandbox escapeChrome's GPU component contains a heap buffer overflow (CWE-787) fixed in version 107.0.5304.121. An attacker who already controls the renderer proce…KEVEPSS 32%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed8.8CVE-2025-5419Google Chrome V8 out-of-bounds read and write enables heap corruptionV8 in Google Chrome before 137.0.7151.68 contains an out-of-bounds read and write that a remote attacker can trigger with a crafted HTML page, leadin…KEVEPSS 7.8%analysed8.8CVE-2024-7965Google Chrome V8 inappropriate implementation allows heap corruptionGoogle Chrome before 128.0.6613.84 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. The flaw is…KEVEPSS 19%analysed8.8CVE-2023-5217libvpx VP8 encoding heap buffer overflow exploited via crafted HTMLA heap buffer overflow in the VP8 encoder in libvpx affects Google Chrome before 117.0.5938.132 and libvpx 1.13.1, and is reachable through a crafted…KEVEPSS 49%analysed8.8CVE-2023-4863libwebp Heap Buffer Overflow via Crafted WebP ImageA heap buffer overflow in libwebp allows an out-of-bounds memory write when processing a crafted WebP image. It affects Google Chrome before 116.0.58…KEVEPSS 100%analysed8.8CVE-2023-4762Google Chrome V8 type confusion enables remote code executionGoogle Chrome before 116.0.5845.179 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and lea…KEVEPSS 41%analysed

Source: NIST National Vulnerability Database (record CVE-2026-58281), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.