Executive brief
Microsoft Edge is a web browser used by millions to access websites and cloud services. A use-after-free vulnerability in Edge's Chromium engine could allow an attacker to elevate privileges and take control of the browser or the underlying system when a user visits a malicious website or opens a specially crafted file.
Technical details
A use-after-free vulnerability exists in the Chromium rendering engine used by Microsoft Edge. The vulnerability occurs when the browser attempts to access memory that has already been freed, potentially leading to memory corruption. An attacker can exploit this flaw remotely by crafting a malicious web page or file; when a user interacts with it, the attacker gains the ability to execute arbitrary code and escalate privileges. The vulnerability is reachable over the network and does not require prior authentication.
Affected products
- Microsoft Edge <UNKNOWN>
Timeline
- 2026-09-15: disclosed