Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw Microsoft Edge based on Chromium. It permits an attacker who can influence the data that the browser processes over a network connection to execute arbitrary code. The flaw can compromise confidentiality, integrity, and availability by allowing an attacker to run malicious code with the privileges of the Edge process, potentially leading to full system takeover. The description explicitly a network, so the attack can target users without local credentials. Based on the description, it is inferred that the attacker can craft network traffic that triggers the use‑after‑free.

Affected Systems

Microsoft Edge (Chromium‑based) is the impacted product. No version range is provided, so any installation that has not received the latest security updates may be susceptible.

Risk and Exploitability

The CVSS score of 7.5 places the vulnerability in the high‑severity category. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via network traffic to Edge, where a crafted payload could exploit the memory error. A determined attacker could use this flaw to gain remote code execution on the affected device. The combination of a high CVSS with a low EPSS suggests that while the flaw is severe, exploitation in the wild is currently unlikely.

Generated by OpenCVE AI on July 21, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edgefree flaw (CWE‑416).
  • Enable automatic updates in Microsoft Edge to ensure continuous protection against this and related vulnerabilities.
  • Restrict or block network connections that interact with Edge to reduce exposure to crafted traffic that could trigger the use‑after‑free flaw.

Generated by OpenCVE AI on July 21, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:56:11.205Z

Reserved: 2026-06-26T17:45:44.855Z

Link: CVE-2026-57992

cve-icon Vulnrichment

Updated: 2026-07-06T11:38:43.206Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses