Junglewise Threat Intelligence

CVE-2026-88097: Microsoft Edge use after free privilege escalation

CVE-2026-88097 · Severity: high · CVSS 8.1 · Published 2026-09-18

Technologies: Microsoft Edge Chromium, Microsoft Edge. Vendors: Microsoft.

Executive brief

Microsoft Edge is a web browser used by millions of users to access internet services and corporate applications. A use-after-free vulnerability allows a local attacker to execute code with elevated privileges on an affected system, potentially giving them administrative control of the device.

Technical details

A use-after-free memory vulnerability in Microsoft Edge's Chromium-based rendering engine allows local code execution with privilege escalation. The vulnerability requires local access to the affected system. An attacker exploiting this flaw can gain elevated privileges and achieve arbitrary code execution on the target device.

Affected products

  • Microsoft Edge

Timeline

  • 2026-09-18: disclosed

References

Related threats