Junglewise Threat Intelligence

CVE-2026-66315: Microsoft Edge use-after-free vulnerability in Chromium

CVE-2026-66315 · Severity: high · CVSS 7.5 · Published 2026-08-04

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users worldwide. A use-after-free memory flaw allows attackers to execute arbitrary code on a user's system simply by serving a malicious webpage, potentially leading to complete system compromise, theft of sensitive data, or malware installation.

Technical details

A use-after-free vulnerability exists in Microsoft Edge's Chromium-based rendering engine, where memory is accessed after being freed, leading to memory corruption. The flaw is reachable over the network and can be triggered by visiting a specially crafted malicious website. An attacker can exploit this vulnerability to achieve arbitrary code execution with the privileges of the user running the browser, without requiring user authentication or special privileges beyond visiting a webpage.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats