Microsoft Edge (Chromium-based) Use-After-Free Vulnerability Leading to Remote Code Execution

Vulnerability

A use-after-free vulnerability has been identified in Microsoft Edge (Chromium-based), allowing an unauthorized attacker to execute code remotely. This vulnerability requires user interaction, as it involves convincing a user to open a specially crafted file or visit a malicious website.

Impact

Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected system.

Reproduction

To reproduce this vulnerability, a user must be convinced to open a specially crafted file or visit a website that exploits the use-after-free condition in Microsoft Edge. This can be done by hosting the malicious content and persuading the user to interact with it, such as through an email or message.

Remediation

Users can download the security update for Microsoft Edge (Chromium-based) from the Microsoft Update Catalog.

Added: Jul 3, 2026, 9:40 PM
Updated: Jul 3, 2026, 9:40 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
4.0
remediation
7.7
relevance
8.4
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.