Skip to content
Multiple Vulnerabilities Discovered in Microsoft Edge Allow Remote Code Execution

Multiple Vulnerabilities Discovered in Microsoft Edge Allow Remote Code Execution

First seen 5 Jun 2026, 09:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 6, 2026 at 08:55 UTC
  • Three critical vulnerabilities in Microsoft Edge disclosed on June 5, 2026.
  • User interaction is required for exploitation, increasing the risk of attack.
  • Vulnerabilities can be combined with others for greater impact.

On June 5, 2026, three vulnerabilities were disclosed affecting Microsoft Edge, allowing remote attackers to execute arbitrary code or access restricted functionality. The vulnerabilities require user interaction, such as visiting a malicious page or opening a malicious file. ZDI-26-331 allows arbitrary code execution via improper handling of feedback log files. ZDI-26-329 enables access to restricted features due to insufficient validation in the cross-device managed sign-in mechanism. ZDI-26-330 permits arbitrary cross-origin script execution due to lack of validation of user-supplied data. All three vulnerabilities can be exploited in conjunction with other flaws, increasing their risk. Users are advised to remain vigilant and apply any patches released by Microsoft. No specific patches have been mentioned in the articles as of the publication date.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 108d ago How this analysis works

Timeline

2026-06-05
ZDI-26-331 disclosed
A vulnerability in Microsoft Edge allows remote code execution through improper handling of feedback log files.
Zerodayinitiative
2026-06-05
ZDI-26-329 disclosed
A vulnerability in Microsoft Edge allows access to restricted functionality due to insufficient validation in sign-in mechanisms.
Zerodayinitiative
2026-06-05
ZDI-26-330 disclosed
A vulnerability in Microsoft Edge allows arbitrary cross-origin script execution due to lack of validation of user-supplied data.
Zerodayinitiative

More articles in this cluster (5)