Executive brief
Microsoft Edge is a web browser used to access the internet and internal corporate applications. A security flaw has been identified that could allow a remote attacker to execute malicious code on a user's computer if they are tricked into visiting a specially crafted website. This could lead to a total compromise of the user's workstation, including the theft of sensitive data or the installation of malware.
Technical details
A use-after-free (CWE-416) vulnerability exists in Microsoft Edge (Chromium-based) prior to version 150.0.4078.48. The flaw is triggered when the browser improperly manages memory during the lifecycle of certain objects, allowing an attacker to reference memory after it has been freed. To exploit this, a remote attacker must entice a user to visit a malicious webpage or click a link (User Interaction required). Successful exploitation allows for remote code execution (RCE) in the context of the browser process. The attack complexity is rated as high, likely due to the need for specific memory layout manipulation or bypassing modern browser mitigations.
Affected products
- Microsoft Edge (Chromium-based) versions before 150.0.4078.48
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory