Junglewise Threat Intelligence

CVE-2026-85893: Microsoft Edge use-after-free in Chromium

CVE-2026-85893 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions to access websites and cloud services. A use-after-free vulnerability in Edge's Chromium engine could allow an attacker to elevate privileges and take control of the browser or the underlying system when a user visits a malicious website or opens a specially crafted file.

Technical details

A use-after-free vulnerability exists in the Chromium rendering engine used by Microsoft Edge. The vulnerability occurs when the browser attempts to access memory that has already been freed, potentially leading to memory corruption. An attacker can exploit this flaw remotely by crafting a malicious web page or file; when a user interacts with it, the attacker gains the ability to execute arbitrary code and escalate privileges. The vulnerability is reachable over the network and does not require prior authentication.

Affected products

  • Microsoft Edge <UNKNOWN>

Timeline

  • 2026-09-15: disclosed

References

Related threats