Impact
A use‑after‑free flaw in Microsoft Edge (Chromium‑based) lets an attacker run arbitrary code in the context of the user who is running the browser. The vulnerability, identified as CWE‑416, arises when Edge incorrectly accesses data after it has been freed. If successfully triggered, an attacker can execute malicious code and potentially take control of the entire system hosting the browser. The flaw appears to be exploitable by delivering specially crafted content over a network connection. It is inferred that user interaction may be required, but the description does not explicitly state this.
Affected Systems
Microsoft Edge (Chromium‑based) on all current releases is affected. No specific version range is supplied, so every existing Edge installation may be vulnerable until a security update that addresses CVE‑2026‑57986 is installed.
Risk and Exploitability
The CVSS score of 7.5 denotes high severity, and an EPSS score of <1% indicates a very low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a malicious or tampered web content delivered over a network. It is inferred that user interaction may be needed, but this is not explicitly stated. The vector is network‑based.
OpenCVE Enrichment