Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-07-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-58294 is a use‑after‑free vulnerability (CWE‑416) in Microsoft Edge (Chromium‑based) that permits an attacker to execute arbitrary code in the context of the browser. The flaw arises when a previously freed memory object is accessed, allowing malicious data to be interpreted as executable code, leading to unrestricted execution capabilities.

Affected Systems

All installations of Microsoft Edge that incorporate the Chromium engine are potentially vulnerable; the advisory does not list specific build or release numbers, so every current Edge version should be treated as at risk until the public security update is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could trigger the flaw by delivering a crafted web page or network payload that causes the browser to encounter the use‑after‑free, enabling remote code execution without authentication.

Generated by OpenCVE AI on August 1, 2026 at 20:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Edge security update released by Microsoft in the Security Response Center update guide.
  • Upgrade Microsoft Edge to the latest stable release to ensure the vulnerability is fully patched.
  • Limit user exposure to untrusted web content by enforcing least privilege for user accounts and deploying content filtering policies.

Generated by OpenCVE AI on August 1, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:53.494Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58294

cve-icon Vulnrichment

Updated: 2026-07-06T11:17:39.643Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:04.293

Modified: 2026-07-07T12:33:42.660

Link: CVE-2026-58294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses