Executive brief
Microsoft Edge is a web browser used by millions to access websites and web applications. A heap memory overflow vulnerability allows attackers to execute arbitrary code on a user's computer by tricking them into visiting a malicious website, potentially leading to data theft, account compromise, or system takeover.
Technical details
A heap-based buffer overflow exists in Microsoft Edge (Chromium-based browser). The vulnerability can be exploited over the network without authentication; an attacker crafts a malicious webpage that, when visited by a user, triggers the overflow condition in memory. This allows arbitrary code execution within the browser process with user privileges. Microsoft has released a security update to address this issue.
Affected products
- Microsoft Edge
Timeline
- 2026-08-14: disclosed