Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Microsoft Edge (Chromium‑based) allows an attacker to execute arbitrary code within the browser process. The vulnerability, classified as CWE‑416, can be exploited over a network connection, granting an unauthorized attacker remote code execution capabilities while the Edge process is running.

Affected Systems

All Microsoft Edge (Chromium‑based) installations that have not yet received the latest security update are vulnerable. No specific version ranges are provided in the advisory, so any build lacking the applied patch may be impacted.

Risk and Exploitability

The CVSS score of 7.5 classifies this as a high severity issue. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered remotely via a network connection, it poses a significant risk in environments where the browser is exposed to untrusted networks.

Generated by OpenCVE AI on August 1, 2026 at 20:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Edge (Chromium‑based) security update that addresses the use‑after‑free flaw.
  • If a patch cannot be applied immediately, isolate the browser from untrusted network traffic or disable it in high‑risk environments.
  • Deploy network segmentation and monitor for anomalous outbound connections or processes spawned by Edge.

Generated by OpenCVE AI on August 1, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:16:17.180Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57984

cve-icon Vulnrichment

Updated: 2026-07-06T11:43:29.112Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:01.550

Modified: 2026-07-07T15:17:01.677

Link: CVE-2026-57984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses