Junglewise Threat Intelligence

CVE-2026-70341: Microsoft Edge use-after-free vulnerability

CVE-2026-70341 · Severity: high · CVSS 8.5 · Published 2026-09-11

Technologies: Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge, a web browser used by millions of users to access websites and web applications, contains a use-after-free memory vulnerability. An attacker with valid credentials could exploit this flaw to execute arbitrary code on a user's computer, potentially leading to unauthorized access to sensitive data, installation of malware, or system compromise.

Technical details

A use-after-free vulnerability exists in Microsoft Edge (Chromium-based) that allows an authorized attacker to execute arbitrary code over the network. This type of vulnerability occurs when a program references memory that has been freed, potentially allowing an attacker to overwrite freed memory with malicious code. The attack requires network connectivity and authorization credentials. Successful exploitation could result in remote code execution with the privileges of the user running Edge. Microsoft has released security updates to patch this vulnerability.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-09-11: disclosed

References

Related threats