Executive brief
Microsoft Edge is a web browser used by millions of users worldwide. A use-after-free memory flaw allows attackers to execute arbitrary code on a user's system simply by serving a malicious webpage, potentially leading to complete system compromise, theft of sensitive data, or malware installation.
Technical details
A use-after-free vulnerability exists in Microsoft Edge's Chromium-based rendering engine, where memory is accessed after being freed, leading to memory corruption. The flaw is reachable over the network and can be triggered by visiting a specially crafted malicious website. An attacker can exploit this vulnerability to achieve arbitrary code execution with the privileges of the user running the browser, without requiring user authentication or special privileges beyond visiting a webpage.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-04: disclosed