Description
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow in Microsoft Edge (Chromium‑based) allows an unauthorized attacker to execute arbitrary code on a compromised system. The flaw occurs when untrusted data overflows a heap buffer used by the rendering engine, providing the attacker full code‑execution privileges. Identified as CWE‑122, this weakness can be triggered by delivering malicious content over a network, giving an attacker remote access to the target device.

Affected Systems

Microsoft Edge (Chromium‑based) installations that have not received the latest security update are susceptible. The advisory does not list specific version numbers, so any instance lacking the update should be considered at risk. Earlier builds not explicitly addressed remain uncertain and may also be vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is < 1%, showing a very low but nonzero likelihood of exploitation. It is not listed in CISA KEV. Based on the description, the likely attack vector is a network attacker sending crafted data to trigger the buffer overflow, allowing remote code execution without requiring elevated privileges.

Generated by OpenCVE AI on July 26, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft update that fixes CVE-2026-56645 to all affected Edge installations.
  • Restart Edge processes or reboot the system after installing the update so the new binaries load.
  • If the update cannot be applied immediately, enforce a group policy that disables or restricts external content and script execution in Edge until the update is available.

Generated by OpenCVE AI on July 26, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-26T17:17:09.685Z

Reserved: 2026-06-22T15:17:38.795Z

Link: CVE-2026-56645

cve-icon Vulnrichment

Updated: 2026-07-06T16:30:45.466Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T22:30:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow