Impact
A use‑after‑free flaw in Microsoft Edge (Chromium‑based) lets an attacker run arbitrary code in the context of the user who is running the browser. The vulnerability, identified as CWE‑416, arises when Edge incorrectly accesses data after it has been freed. If successfully triggered, an attacker can execute malicious code and potentially take control of the entire system hosting the browser. The flaw is exploitable by delivering specially crafted content over a network connection, enabling the attacker to manipulate the browser without user interaction.
Affected Systems
Microsoft Edge (Chromium‑based) on all current releases is affected. No specific version range is supplied, so every existing Edge installation may be vulnerable until a security update that addresses CVE‑2026‑57986 is installed.
Risk and Exploitability
The CVSS score of 7.5 denotes high severity, and an EPSS score of <1% indicates a very low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it can be triggered by unwitting users who load malicious or tampered web content, giving the attacker a network‑based attack vector to the browser.
OpenCVE Enrichment