Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Microsoft Edge (Chromium‑based) allows an attacker to cause the browser to access memory that has already been released, paving the way for arbitrary code execution. The flaw allows an unauthorized attacker to exploit it over a network.

Affected Systems

Microsoft Edge (Chromium‑based) is affected; no specific version ranges were supplied.

Risk and Exploitability

The CVSS score of 7.5 signals high severity less than 1 % indicates a very low likelihood of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalog, and no large‑scale incidents are documented. Based on the description, the attack is inferred to be triggered by a malicious document or a crafted URL delivered over the network, which would enable remote code execution on the host.

Generated by OpenCVE AI on July 21, 2026 at 09:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that contains the fix for the use‑after‑free bug as soon as it becomes available.
  • Ensure Microsoft Edge’s automatic update feature is enabled so future security patches are installed without manual intervention.
  • Deploy endpoint protection or web‑filtering controls to detect and block malicious content that might trigger the vulnerability.

Generated by OpenCVE AI on July 21, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:56:11.802Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58276

cve-icon Vulnrichment

Updated: 2026-07-06T11:30:38.241Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses