Junglewise Threat Intelligence

CVE-2026-69486: Microsoft Edge heap-based buffer overflow

CVE-2026-69486 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users to access web content and applications. A heap-based buffer overflow vulnerability allows attackers to execute malicious code on a user's computer by crafting a malicious webpage or content that the user visits over the internet, potentially compromising personal data, credentials, and system security.

Technical details

A heap-based buffer overflow vulnerability exists in the memory management of Microsoft Edge (Chromium-based). The vulnerability allows an attacker to write beyond allocated heap memory boundaries, leading to arbitrary code execution. The attack requires no authentication and can be triggered remotely when a user visits a malicious website or opens malicious content. An attacker can exploit this to achieve code execution with the privileges of the Edge browser process. Microsoft has released or will release security patches to address this vulnerability.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats