Description
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via heap-based buffer overflow.
Action: Immediate Patch
AI Analysis

Impact

Microsoft Edge (Chromium-based) contains a heap-based buffer overflow that allows an unauthorized attacker to execute arbitrary code on a target system. When the browser parses malformed network data, the overflow can be triggered without user interaction, enabling the attacker to inject and run malicious code within the browser process. This flaw grants full access to the system, compromising confidentiality, integrity, and availability of the affected machine.

Affected Systems

The vulnerability impacts Microsoft Edge (Chromium-based) distributed by Microsoft. No version range is specified in the advisory, so all current releases of the Chromium‑based Edge browser are potentially affected until a patch is installed.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score of less than 1% indicates that, although the attack is theoretically possible, real‑world exploitation is currently unlikely but still feasible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over the network, most likely through a malicious web page or content that the browser processes, requiring no special privileges or user interaction beyond normal browsing activity.

Generated by OpenCVE AI on September 18, 2026 at 13:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Microsoft Edge to the latest version released by Microsoft.
  • Apply all current Windows cumulative security updates to keep related components current.
  • Restrict the execution of untrusted content by configuring the browser’s security settings or using group policy to block potentially malicious sites and disable legacy content.

Generated by OpenCVE AI on September 18, 2026 at 13:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-07T15:00:02.016Z

Reserved: 2026-08-03T21:07:24.908Z

Link: CVE-2026-69486

cve-icon Vulnrichment

Updated: 2026-09-16T19:00:57.251Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T23:17:41.633

Modified: 2026-09-25T19:36:56.480

Link: CVE-2026-69486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:15:06Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow