Junglewise Threat Intelligence

CVE-2026-57981: Microsoft Edge use after free remote code execution

CVE-2026-57981 · Severity: high · CVSS 8.8 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that could allow an attacker to execute malicious code on a user's computer if they are tricked into visiting a specially crafted website. This could lead to a total compromise of the user's workstation, including the theft of sensitive data or the installation of malware.

Technical details

A use-after-free (UAF) vulnerability exists in Microsoft Edge (Chromium-based) due to improper memory management. An attacker can exploit this by hosting a malicious website and inducing a user to visit it (User Interaction required). Successful exploitation allows the attacker to execute arbitrary code in the context of the browser process. The vulnerability is tracked as CWE-416 and has been addressed in versions 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) < 150.0.4078.48

Timeline

  • 2026-07-03: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats