Description
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Published: 2026-08-14
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in Microsoft Edge (Chromium-based) that allows an unauthorized attacker to execute arbitrary code over a network. This flaw stems from improper memory handling during processing of web content, classified as CWE-122, and can lead to full compromise of the affected system if the attacker succeeds.

Affected Systems

The affected vendor is Microsoft, specifically the Edge browser built on the Chromium engine. No specific version range is listed in the advisory, so all installations of the Chromium‑based Edge that are not updated to the latest release may be vulnerable.

Risk and Exploitability

The assessment shows a CVSS score of 8.3, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered over a network and an attacker does not need local privileges, the likelihood of exploitation is significant for systems exposed to the Internet.

Generated by OpenCVE AI on August 14, 2026 at 19:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge security update released by Microsoft and follow the guidance on Microsoft’s update guide.
  • Ensure automatic updates are enabled for Edge, for example by activating Windows Update for Enterprise or configuring Group Policy to enforce application updates.
  • Apply application control or enable Runtime Application Self‑Protection to block execution of unknown code until the patch is installed.

Generated by OpenCVE AI on August 14, 2026 at 19:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Title Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-03T21:22:17.025Z

Reserved: 2026-08-10T18:36:42.030Z

Link: CVE-2026-72970

cve-icon Vulnrichment

Updated: 2026-08-14T18:51:36.749Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-14T18:19:09.003

Modified: 2026-08-18T12:23:07.260

Link: CVE-2026-72970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:15:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow