Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege via Use After Free
Action: Apply Patch
AI Analysis

Impact

A use‑after‑free flaw exists in Microsoft Edge (Chromium‑based) that allows an attacker with network proximity to a victim to elevate privileges. By triggering the memory management bug, the attacker can obtain higher authority on the target system beyond the privileges originally granted to the user. This breach of integrity can lead to further exploitation, data theft, or persistent footh After Free, classified as CWE‑416.

Affected Systems

The vulnerability impacts Microsoft Edge (Chromium‑based) on any affected version for which a patch has not yet been installed. Current version information is not specified in the advisory, so all installations using the Chromium‑based Edge build must be considered at risk until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity issue. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑proximate attacker that can lure or manipulate a user into visiting a malicious site or loading malicious content in Edge. Because it is a memory‑corruption bug, exploitation requires code‑execution capabilities that may not be readily available to all threat actors, further reducing risk but not eliminating it.

Generated by OpenCVE AI on September 18, 2026 at 13:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update through Windows Update or the Microsoft Edge update channel.
  • Configure Windows Update to automatically download and install updates for Microsoft Edge, ensuring that future patches are applied promptly.
  • Deploy web‑filtering or Microsoft Defender for Endpoint to block or detect malicious URLs that could exploit the vulnerability.

Generated by OpenCVE AI on September 18, 2026 at 13:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-01T23:01:15.377Z

Reserved: 2026-09-04T18:18:19.328Z

Link: CVE-2026-85893

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:27.699Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T23:19:12.110

Modified: 2026-09-25T19:37:48.200

Link: CVE-2026-85893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:15:06Z

Weaknesses