Impact
CVE-2026-58294 is a use‑after‑free flaw (CWE-416) in Microsoft Edge (Chromium-based) that permits vulnerability qualifies as a remote code execution risk.
Affected Systems
All builds of Microsoft Edge that incorporate the Chromium engine are potentially vulnerable until a patch is applied. The advisory does not specify individual version numbers, so enterprises should treat every current Edge installation as at risk.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could trigger the flaw by delivering a crafted web page or network payload that causes the browser to suffer the use‑after‑free, enabling remote code execution without authentication.
OpenCVE Enrichment