Description
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via a heap-based buffer overflow.
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow exists in Microsoft Edge (Chromium-based), enabling an unauthorized attacker to execute arbitrary code. The flaw is triggered by malformed data processed over the network, allowing malicious code injection into the browser process and leading to complete compromise of the affected system's confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects Microsoft Edge (Chromium-based) as distributed by Microsoft. No specific version range is detailed in the advisory, implying that all current releases of the Chromium-based Edge browser are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as High severity. The EPSS indicator of less than 1% suggests that real-world exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over the network, most likely via a malicious or compromised web page or exploited content reaching the browser’s parsing routines. Given the absence of, yet the potential impact justifies prioritizing remediation.

Generated by OpenCVE AI on September 16, 2026 at 19:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version released by Microsoft as soon as possible.
  • Install the latest cumulative Windows security updates to ensure all related components are up‑to‑date.
  • Configure anti-malware and browser security settings to block or alert on suspicious content and prevent execution of untrusted code.

Generated by OpenCVE AI on September 16, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-17T03:57:03.422Z

Reserved: 2026-08-03T21:07:24.908Z

Link: CVE-2026-69486

cve-icon Vulnrichment

Updated: 2026-09-16T19:00:57.251Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T23:17:41.633

Modified: 2026-09-17T04:17:55.620

Link: CVE-2026-69486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:00:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow