Description
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Published: 2026-09-11
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Microsoft Edge (Chromium-based) contains a use‑after‑free vulnerability that allows an authorized attacker to execute arbitrary code remotely. The flaw can be triggered when the browser processes certain network artifacts, leading to full code execution in the user's context. This weakness aligns with CWE‑416.

Affected Systems

The vulnerability affects Microsoft Edge (Chromium-based) on Windows, Android, iOS, Linux, and macOS. Product versions are not explicitly listed in the advisory, so all currently deployed releases are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting it is not a widely exploited or actively targeted flaw at this time. However, the presence of a use‑after‑free that enables remote code execution means the exploit could have devastating consequences if an attacker achieves the necessary authorized network access. The attack vector is likely remote, via malicious web content or network requests sent to the browser.

Generated by OpenCVE AI on September 11, 2026 at 17:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Microsoft Edge to the latest version via Windows Update, Microsoft Store, or the relevant app store for Android/iOS.
  • Verify that automatic updates are enabled for Edge on all platforms to receive future fixes promptly.
  • If Edge is not required, uninstall the browser or restrict its use until the update is installed.

Generated by OpenCVE AI on September 11, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Edge (chromium-based)
Vendors & Products Microsoft microsoft Edge (chromium-based)

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge:*:*:*:*:*:android:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:linux:*:*
cpe:2.3:a:microsoft:edge:*:*:*:*:*:mac:*:*
cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Edge Chromium Microsoft Edge (chromium-based)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-29T20:22:54.100Z

Reserved: 2026-08-04T00:04:56.037Z

Link: CVE-2026-70341

cve-icon Vulnrichment

Updated: 2026-09-12T15:32:42.326Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T16:17:46.080

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-70341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:15:14Z

Weaknesses