Junglewise Threat Intelligence

CVE-2026-72970: Microsoft Edge heap-based buffer overflow

CVE-2026-72970 · Severity: high · CVSS 8.3 · Published 2026-08-14

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions to access websites and web applications. A heap memory overflow vulnerability allows attackers to execute arbitrary code on a user's computer by tricking them into visiting a malicious website, potentially leading to data theft, account compromise, or system takeover.

Technical details

A heap-based buffer overflow exists in Microsoft Edge (Chromium-based browser). The vulnerability can be exploited over the network without authentication; an attacker crafts a malicious webpage that, when visited by a user, triggers the overflow condition in memory. This allows arbitrary code execution within the browser process with user privileges. Microsoft has released a security update to address this issue.

Affected products

  • Microsoft Edge

Timeline

  • 2026-08-14: disclosed

References

Related threats