Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege via Use After Free
Action: Apply Patch
AI Analysis

Impact

A use‑after‑free flaw exists in Microsoft Edge (Chromium‑based) that allows an attacker with network proximity to a victim to elevate privileges. By triggering the memory management bug, the attacker can obtain higher authority on the target system beyond the privileges originally granted to the user. This breach of integrity can lead to further exploitation, data theft, or persistent footh After Free, classified as CWE‑416.

Affected Systems

The vulnerability impacts Microsoft Edge (Chromium‑based) on any affected version for which a patch has not yet been installed. Current version information is not specified in the advisory, so all installations using the Chromium‑based Edge build must be considered at risk until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity issue. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑proximate attacker that can lure or manipulate a user into visiting a malicious site or loading malicious content in Edge. Because it is a memory‑corruption bug, exploitation requires code‑execution capabilities that may not be readily available to all threat actors, further reducing risk but not eliminating it.

Generated by OpenCVE AI on September 16, 2026 at 20:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update through Windows Update or the Microsoft Edge update channel.
  • Configure Windows Update to automatically download and install updates for Microsoft Edge, ensuring that future patches are applied promptly.
  • Deploy web‑filtering or Microsoft Defender for Endpoint to block or detect malicious URLs that could exploit the vulnerability.

Generated by OpenCVE AI on September 16, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-17T03:57:02.054Z

Reserved: 2026-09-04T18:18:19.328Z

Link: CVE-2026-85893

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T23:19:12.110

Modified: 2026-09-17T04:18:02.687

Link: CVE-2026-85893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:30:06Z

Weaknesses