Description
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Published: 2026-07-01
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Microsoft Edge ( a use‑after‑free that, if successfully exploited, allows an attacker with authorized network access to execute arbitrary code within the Edge process. The flaw is classified as CWE‑416, indicating a failure to properly free and manage memory. By exploiting this condition, an attacker can gain full control of the system running the browser, potentially leading to disclosure, modification, or disruption of data and services.

Affected Systems

All current releases of Microsoft Edge (Chromium‑based) on Microsoft Windows and other supported operating systems are potentially affected. No specific product versions are listed in the available data, so the vulnerability applies broadly until an official patch is released by Microsoft.

Risk and Exploitability

The CVSS score of 8.3 reflects a high severity scenario for remote code execution. The EPSS score of less than 1 % indicates a very low, but non‑zero, likelihood of exploitation observed in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must be able to connect to the target system with authorized network access to Edge; the attack vector is inferred to be network‑based, exploiting memory corruption via the use‑after‑free condition.

Generated by OpenCVE AI on July 21, 2026 at 13:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge patch or security update to eliminate the use‑after‑free flaw identified as CWE‑416.
  • Enable browser sandboxing and ensure operating system mitigations such as ASLR, DEP, and default memory protection are active to reduce the impact of any remaining memory errors.
  • Restrict unauthorized network access to Edge using firewalls, group‑ restrictions, or application whitelisting to limit exposure to malicious traffic.
  • Monitor Edge and system logs for unusual memory‑corruption events or abnormal process activity, and investigate any anomalies promptly.

Generated by OpenCVE AI on July 21, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-15T20:10:14.417Z

Reserved: 2026-06-04T19:00:41.293Z

Link: CVE-2026-50521

cve-icon Vulnrichment

Updated: 2026-07-02T14:40:06.173Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:30:07Z

Weaknesses