Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free bug that allows an attacker who can reach the browser over a network to execute arbitrary code. The impact is the compromise of confidentiality and integrity of the victim machine. The weakness is classified as CWE-416.

Affected Systems

Microsoft Edge (Chromium‑based) from Microsoft is affected. Version information is not supplied in the data, so any installation of Edge the relevant update after the disclosure date could be at risk.

Risk and Exploitability

The CVSS score of 8.3, a high severity, while the EPSS score of < 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread attacks yet. The likely attack vector is remote over a network, as the description specifies that code execution is possible from a remote endpoint.

Generated by OpenCVE AI on July 21, 2026 at 09:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge security update that addresses CVE‑2026‑58288.
  • Restrict inbound network traffic to the Edge process by configuring firewalls to block connections that could exploit the use‑after‑free flaw.
  • Disable or limit the use of Edge from untrusted remote desktop browser logs for signs of exploitation attempts and review for abnormal browser behavior.

Generated by OpenCVE AI on July 21, 2026 at 09:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:38.744Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58288

cve-icon Vulnrichment

Updated: 2026-07-06T11:26:01.384Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses