Executive brief
Microsoft Edge is a web browser used by millions to access websites and online services. A use-after-free vulnerability could allow an attacker to execute malicious code on a user's computer through a specially crafted webpage, potentially leading to data theft, credential compromise, or malware installation.
Technical details
A use-after-free vulnerability exists in Microsoft Edge (Chromium-based) where freed memory is accessed after deallocation, potentially causing memory corruption. The vulnerability can be exploited over the network by an attacker without authentication by serving a malicious webpage that triggers the vulnerable code path. Successful exploitation allows arbitrary code execution in the browser process with user privileges. Microsoft has released a security update addressing this issue.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-08-28: disclosed