Junglewise Threat Intelligence

CVE-2026-58287: Microsoft Edge use after free remote code execution

CVE-2026-58287 · Severity: high · CVSS 8.3 · Published 2026-07-03

Technologies: Microsoft Edge (Chromium-based). Vendors: Microsoft.

Executive brief

Microsoft Edge, the primary web browser for Windows systems, is affected by a security flaw that could allow an attacker to take control of a user's computer. By tricking a user into visiting a malicious website or clicking a specific link, an attacker could execute unauthorized commands on the victim's device. This could lead to the theft of sensitive personal data, installation of malware, or full system compromise.

Technical details

A use-after-free (CWE-416) vulnerability exists in Microsoft Edge (Chromium-based) due to improper memory management. The flaw is exploitable over the network, though it requires a high degree of attack complexity and user interaction, such as convincing a victim to visit a specially crafted website. If successfully exploited, the attacker can achieve remote code execution (RCE) within the context of the browser process, potentially escaping the sandbox to compromise the underlying operating system. Microsoft has addressed this in versions 150.0.4078.48 and later.

Affected products

  • Microsoft Edge (Chromium-based) 1.0.0.0 to 150.0.4078.48

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats