CVE-2026-66315
Microsoft · Microsoft Edge (Chromium-based)
A use after free vulnerability in Microsoft Edge allows an unauthenticated attacker to execute code over a network via a specially crafted web page.
Executive summary
A high severity use after free vulnerability in Microsoft Edge (Chromium-based) could allow an unauthenticated attacker to execute arbitrary code on the host system.
Vulnerability
This vulnerability (CWE-416) involves a use after free flaw in the browser engine. An unauthenticated attacker can exploit this by enticing a user to navigate to a malicious website.
Business impact
With a CVSS score of 7.5, this vulnerability presents a significant threat to organizational security. Successful exploitation could lead to total browser compromise, potential host system access, and the exfiltration of sensitive session data or credentials stored within the browser environment.
Remediation
Immediate Action: Update the Microsoft Edge browser to version 151.0.4129.59 or later immediately.
Proactive Monitoring: Review web proxy and firewall logs for traffic directed toward known malicious or suspicious domains.
Compensating Controls: Deploy browser-based security policies that restrict script execution or leverage secure browsing configurations to minimize the impact of potential browser-based attacks.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given that web browsers are primary attack surfaces, immediate patching is required. Administrators should ensure that automatic updates are enabled for all managed browser instances to prevent exploitation.