Impact
Microsoft Edge (Chromium‑based) contains a use‑after‑free vulnerability that an attacker able to execute code locally can exploit to elevate privileges. The flaw allows the attacker to read, modify or otherwise tamper with data belonging to higher‑privilege processes, potentially giving them the ability to run arbitrary code or gain administrative rights on the affected system.
Affected Systems
All releases of Microsoft Edge that are built on the Chromium engine are potentially affected; the advisory does not specify particular versions, so any installed instance could be vulnerable until the fix is applied.
Risk and Exploitability
The flaw has a CVSS score of 8.1 and an EPSS score of less than 1 %, indicating a high severity yet a low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The description states that use‑after‑free allows an attacker with local code execution to elevate privileges. Based on this description, we infer that the attacker would need to execute code locally, typically by visiting a malicious web page or opening a crafted document that triggers the use‑after‑free. Once executed, the attacker can abuse the freed memory to gain elevated privileges on the local machine.
OpenCVE Enrichment