Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that could allow an authorized user to execute unauthorized code over the network. This could lead to a compromise of the user's computer, potentially resulting in data theft or unauthorized access to corporate systems.
Technical details
A use-after-free vulnerability (CWE-416) exists in Microsoft Edge (Chromium-based) prior to version 149.0.4022.68. The flaw is triggered when the browser incorrectly manages memory during certain operations, allowing an attacker with low-level authentication to execute arbitrary code via the network. The attack vector is network-based and does not require user interaction, though it does require the attacker to have some level of authorization (PR:L). Successful exploitation can lead to high impacts on confidentiality and integrity. Users should update to version 149.0.4022.68 or later to mitigate this risk.
Affected products
- Microsoft Edge (Chromium-based) versions before 149.0.4022.68
Timeline
- 2026-07-01: disclosed: Initial publication of the CVE record.
- 2026-07-01: advisory: Microsoft released the security update guide for this vulnerability.