Executive brief
A security vulnerability exists in the Microsoft Edge web browser that could allow an attacker to execute malicious code on a user's computer. To exploit this, an attacker would typically need to trick a user into visiting a specially crafted website or clicking a malicious link. If successful, the attacker could gain the same level of access as the logged-in user, potentially leading to data theft or full system compromise.
Technical details
A use-after-free (CWE-416) vulnerability exists in Microsoft Edge (Chromium-based) versions prior to 150.0.4078.48. The flaw occurs when the browser continues to use a memory pointer after it has been freed, which can be leveraged by a remote attacker to achieve arbitrary code execution. The attack vector is network-based and requires no prior authentication, though it does require user interaction (UI:R), such as visiting a malicious webpage. The complexity is rated as high (AC:H), suggesting specific timing or environmental conditions are necessary for successful exploitation. Microsoft has released updates to address this issue.
Affected products
- Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48
Timeline
- 2026-07-03: advisory: Initial disclosure by Microsoft and NVD publication.