CVE-2026-72970

8.3

Microsoft · Microsoft Edge (Chromium-based)

A heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthenticated remote attacker to execute arbitrary code via a crafted network request.

Executive summary

A critical heap-based buffer overflow in Microsoft Edge could allow an unauthenticated attacker to achieve remote code execution.

Vulnerability

This is a heap-based buffer overflow (CWE-122) occurring within the browser's memory management. The vulnerability permits an unauthenticated attacker to trigger a crash or execute arbitrary code, requiring only user interaction to process malicious content.

Business impact

The CVSS score of 8.3 reflects a high severity risk that could lead to full system compromise. Successful exploitation allows unauthorized actors to execute code with the privileges of the victim, potentially leading to data exfiltration, lateral movement within the network, and complete loss of system integrity.

Remediation

Immediate Action: Update Microsoft Edge (Chromium-based) to version 151.0.4129.86 or later immediately to resolve the overflow vulnerability.

Proactive Monitoring: Monitor endpoint logs for suspicious process execution patterns or abnormal browser crashes that may indicate exploitation attempts.

Compensating Controls: Deploy browser-based security policies that restrict loading of untrusted content and utilize endpoint detection and response (EDR) solutions to identify anomalous child process spawning.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the high severity and the potential for remote code execution, organizations must prioritize patching all instances of Microsoft Edge. Ensure that automated update channels are functioning correctly and verify that the browser version is updated to 151.0.4129.86 across all enterprise environments to mitigate this risk.

More Microsoft CVEs