Description
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation through a use‑after‑free flaw
Action: Immediate Patch
AI Analysis

Impact

Microsoft Edge (Chromium‑based) contains a use‑after‑free vulnerability that an attacker able to execute code locally can exploit to elevate privileges. The flaw allows the attacker to read, modify or otherwise tamper with data belonging to higher‑privilege processes, potentially giving them the ability to run arbitrary code or gain administrative rights on the affected system.

Affected Systems

All releases of Microsoft Edge that are built on the Chromium engine are potentially affected; the advisory does not specify particular versions, so any installed instance could be vulnerable until the fix is applied.

Risk and Exploitability

The flaw has a CVSS score of 8.1 and an EPSS score of less than 1 %, indicating a high severity yet a low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The description states that use‑after‑free allows an attacker with local code execution to elevate privileges. Based on this description, we infer that the attacker would need to execute code locally, typically by visiting a malicious web page or opening a crafted document that triggers the use‑after‑free. Once executed, the attacker can abuse the freed memory to gain elevated privileges on the local machine.

Generated by OpenCVE AI on September 19, 2026 at 14:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that includes the security fix.
  • Restrict the use of untrusted web content by running Edge in a sandboxed or isolated environment and by enforcing strict content security policies.
  • Limit local user privileges and implement least‑privilege controls so that even if the flaw is exploited, the impact is contained.

Generated by OpenCVE AI on September 19, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
Title Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-416
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:20:34.078Z

Reserved: 2026-09-09T21:51:51.953Z

Link: CVE-2026-88097

cve-icon Vulnrichment

Updated: 2026-09-19T13:59:19.149Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T21:18:45.913

Modified: 2026-09-24T20:48:00.600

Link: CVE-2026-88097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:20Z

Weaknesses