Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free (CWE-416) allows an attacker to corrupt memory and execute arbitrary code remotely, resulting in full system compromise, data breach, or service interruption.

Affected Systems

Microsoft Edge (Chromium‑based) may be impacted. Administrators should consult Microsoft’s security update guide to determine which installations require patching.

Risk and Exploitability

The CVSS score of 8.3 marks this vulnerability as High severity. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation, and the issue, it is inferred that the attack vector is remote over the network, likely requiring an attacker to deliver a crafted network resource that triggers the use‑after‑free. While low in current exploitation probability, the serious impact justifies immediate remediation.

Generated by OpenCVE AI on July 21, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Microsoft Edge security update available through the Microsoft Security Response Center
  • If a patch, isolate Edge connections to the external network or disable the vulnerable feature or restrict web content that could trigger the exploit
  • Enable Windows defenses such as Data Execution Prevention and address space layout randomization to make exploitation more difficult

Generated by OpenCVE AI on July 21, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:34:27.036Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58287

cve-icon Vulnrichment

Updated: 2026-07-06T16:31:27.074Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:30:04Z

Weaknesses