Microsoft Edge (Chromium-based) Use-After-Free Vulnerability Leading to Remote Code Execution

Vulnerability

A use-after-free vulnerability has been identified in Microsoft Edge (Chromium-based) versions through 150.0.4078.48. This vulnerability allows an unauthorized attacker to execute code remotely over the network. Exploitation requires user interaction, specifically convincing a user to open a specially crafted file or visit a malicious website.

Impact

Exploitation of this vulnerability could lead to remote code execution on the affected system.

Reproduction

To reproduce this vulnerability, a user must be convinced to open a specially crafted file or visit a malicious website using Microsoft Edge (Chromium-based) version 150.0.4078.48. Once the file is opened or the website is visited, the vulnerability can be exploited, potentially leading to unauthorized code execution.

Remediation

Users can download the security update for Microsoft Edge (Chromium-based) from the Microsoft Edge Release Notes - Security page.

Added: Jul 3, 2026, 9:36 PM
Updated: Jul 3, 2026, 9:36 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.0
remediation
7.7
relevance
8.8
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.