Junglewise Threat Intelligence

CVE-2026-66798: Microsoft Edge use-after-free in Chromium

CVE-2026-66798 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions to access websites and online services. A use-after-free vulnerability could allow an attacker to execute malicious code on a user's computer through a specially crafted webpage, potentially leading to data theft, credential compromise, or malware installation.

Technical details

A use-after-free vulnerability exists in Microsoft Edge (Chromium-based) where freed memory is accessed after deallocation, potentially causing memory corruption. The vulnerability can be exploited over the network by an attacker without authentication by serving a malicious webpage that triggers the vulnerable code path. Successful exploitation allows arbitrary code execution in the browser process with user privileges. Microsoft has released a security update addressing this issue.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-08-28: disclosed

References

Related threats