Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that could allow an attacker to execute malicious code on a user's computer if they are tricked into visiting a specially crafted website. This could lead to a total compromise of the user's workstation, including the theft of sensitive data or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability exists in Microsoft Edge (Chromium-based) due to improper memory management. An attacker can exploit this by hosting a malicious website and inducing a user to visit it (User Interaction required). Successful exploitation allows the attacker to execute arbitrary code in the context of the browser process. The vulnerability is tracked as CWE-416 and has been addressed in versions 150.0.4078.48 and later.
Affected products
- Microsoft Edge (Chromium-based) < 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial advisory published by Microsoft and NVD.