Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free vulnerability in Microsoft Edge’s Chromium engine that lets an attacker trigger memory corruption from crafted network traffic. This can lead to arbitrary code execution running with the privileges of the Edge process, exposing the confidentiality, integrity, and availability of the device. The flaw is identified as CWE‑416.

Affected Systems

Microsoft Edge (Chromium‑based) is the affected product. No specific version range is listed, meaning any installation that has not applied the latest security update could be at risk.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be over a network connection that the browser can receive, so even without local credentials an attacker can send malicious traffic to provoke the use‑after‑free and achieve remote code execution.

Generated by OpenCVE AI on August 1, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft Edge security update that addresses CVE-2026-57992.
  • Enable automatic updates for Microsoft Edge to receive future patches promptly.
  • Restrict or filter network traffic that interacts with Edge, such as blocking unnecessary ports or applying firewall rules, to reduce the chance of exploited network payloads arriving at the browser.

Generated by OpenCVE AI on August 1, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:16:22.909Z

Reserved: 2026-06-26T17:45:44.855Z

Link: CVE-2026-57992

cve-icon Vulnrichment

Updated: 2026-07-06T11:38:43.206Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:02.310

Modified: 2026-07-07T12:41:39.633

Link: CVE-2026-57992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses