Impact
CVE-2026-58294 is a use‑after‑free vulnerability (CWE‑416) in Microsoft Edge (Chromium‑based) that permits an attacker to execute arbitrary code in the context of the browser. The flaw arises when a previously freed memory object is accessed, allowing malicious data to be interpreted as executable code, leading to unrestricted execution capabilities.
Affected Systems
All installations of Microsoft Edge that incorporate the Chromium engine are potentially vulnerable; the advisory does not list specific build or release numbers, so every current Edge version should be treated as at risk until the public security update is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could trigger the flaw by delivering a crafted web page or network payload that causes the browser to encounter the use‑after‑free, enabling remote code execution without authentication.
OpenCVE Enrichment