Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw (CWE‑416) in Microsoft Edge (Chromium‑based) allows memory corruption that can be leveraged by an attacker to execute arbitrary code. This vulnerability is triggered by loading a specially crafted web resource, and it can lead to full system compromise, data theft, or service disruption for the user whose browser is affected.

Affected Systems

Microsoft Edge (Chromium‑based) is the affected product. The Microsoft Security Response Center provides version ranges that require the update; specific CVE‑affected releases are listed only in the advisory, and all supported Chromium‑based Edge builds are susceptible.

Risk and Exploitability

The CVSS score of 8.3 classifies the flaw as High severity. The EPSS score of less than 1% indicates a low, but non-zero, probability of exploitation. The vulnerability is listed as not in the CISA KEV catalog. It is inferred that the exploit requires a remote network attacker able to deliver a malicious page or resource to the victim's Edge instance; given the low exploitation probability, immediate mitigation is still warranted to prevent potential high‑impact attacks.

Generated by OpenCVE AI on July 31, 2026 at 14:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge security update released through the Microsoft Security Response Center.
  • Until the update can be applied, restrict Edge from accessing untrusted internet traffic or block external web content that could trigger the flaw.
  • Configure Windows Defender Exploit Guard to enable Data Execution Prevention and ensure Address Space Layout Randomization is active.

Generated by OpenCVE AI on July 31, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:49.645Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58287

cve-icon Vulnrichment

Updated: 2026-07-06T16:31:27.074Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:03.413

Modified: 2026-07-07T12:40:42.487

Link: CVE-2026-58287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T14:45:03Z

Weaknesses