Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Microsoft Edge (Chromium‑based) allows an unauthorized attacker to trigger memory corruption. The flaw permits execution of arbitrary code in the Edge process, potentially compromising user data or enabling malicious actions within the browser. The weakness is a classic use‑after‑free error (CWE‑416).

Affected Systems

All users who have installed any build of the Chromium‑based Microsoft Edge on supported operating systems are potentially affected. The advisory does not list affected versions, so it is unclear which specific releases contain the flaw; version information is currently unavailable.

Risk and Exploitability

The CVSS score of 8.8 denotes high severity, while the EPSS score of < 1 % indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. To exploit the flaw, an attacker must deliver crafted data to Edge over the network – the exact point of entry is not detailed, but it could involve a network‑based payload directed at Edge. Once the memory error is triggered, code can run with the privileges of the Edge process.

Generated by OpenCVE AI on August 1, 2026 at 20:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Microsoft Edge to the latest release that contains the fix for CVE‑2026‑57981.
  • Enable automatic updates for Microsoft Edge and Windows to ensure future patches are applied promptly.
  • Limit the exposure of the browser to untrusted network traffic by configuring firewall rules or network segmentation to block or restrict potentially malicious input until the update is applied.

Generated by OpenCVE AI on August 1, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:16:16.085Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57981

cve-icon Vulnrichment

Updated: 2026-07-06T11:33:03.969Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:01.313

Modified: 2026-07-07T15:12:44.373

Link: CVE-2026-57981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses