Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-08-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use after free vulnerability in Microsoft Edge (Chromium‑based) permits an unauthorized attacker to execute code over the network. Triggered by malicious web content, the flaw arises from improper memory deallocation, allowing the attacker to run arbitrary code within the browser process. The primary consequence is remote code execution, potentially compromising the confidentiality, integrity, and availability of the user’s data and the underlying operating system if escalation occurs.

Affected Systems

Microsoft Edge (Chromium‑based) is the affected product. The data does not specify particular version ranges; no release information is provided. Administrators should verify the installed Edge version and consult Microsoft for any applicable security updates.

Risk and Exploitability

CVSS base score of 4.3 indicates low severity. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The probable attack vector is a network‑based exploitation triggered by loading malicious content in Edge. Success requires the victim to visit a compromised page, so the risk is confined to exposed users. Nevertheless, because the issue can lead to remote code execution, it is prudent to monitor for related attacks and apply patches when available.

Generated by OpenCVE AI on August 28, 2026 at 21:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge security updates from Microsoft Update or the official Edge channel.
  • Keep SmartScreen and Enhanced Protection enabled to block malicious web content and reduce the effectiveness of use‑after‑free exploitation.
  • Disable or remove third‑party extensions that could inject code into the browser environment, limiting further attack surface.

Generated by OpenCVE AI on August 28, 2026 at 21:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in cluster-backup-operator. A namespace administrator in open-cluster-management-backup can create a Restore Custom Resource (CR) with malicious hooks. These hooks allow the execution of arbitrary commands within any matching restored pod, leading to the exfiltration of ServiceAccount tokens. This bypasses normal access controls, granting the attacker unauthorized execution access to pods and their associated Service Accounts. Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C'}


Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in cluster-backup-operator. A namespace administrator in open-cluster-management-backup can create a Restore Custom Resource (CR) with malicious hooks. These hooks allow the execution of arbitrary commands within any matching restored pod, leading to the exfiltration of ServiceAccount tokens. This bypasses normal access controls, granting the attacker unauthorized execution access to pods and their associated Service Accounts.
Title cluster-backup-operator: cluster-backup-operator: Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods
Weaknesses CWE-77
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-01T14:48:30.129Z

Reserved: 2026-07-27T19:02:26.600Z

Link: CVE-2026-66798

cve-icon Vulnrichment

Updated: 2026-08-28T20:33:06.439Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T20:19:34.673

Modified: 2026-09-01T15:17:23.257

Link: CVE-2026-66798

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T00:00:00Z

Links: CVE-2026-66798 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T11:15:18Z

Weaknesses
  • CWE-416

    Use After Free

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')