CVE-2026-85893
8.8Microsoft · Microsoft Edge (Chromium-based)
A use after free vulnerability in Microsoft Edge allows an unauthorized attacker to potentially elevate privileges over a network.
Executive summary
A high-severity use after free vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to elevate privileges, posing a significant risk to system integrity.
Vulnerability
This is a use after free memory corruption flaw (CWE-416) within the Microsoft Edge browser. The vulnerability can be triggered by an unauthorized attacker over a network, requiring user interaction to execute.
Business impact
Successful exploitation of this vulnerability could allow an attacker to gain elevated privileges on the host system, potentially leading to unauthorized access to sensitive data or full system compromise. With a CVSS score of 8.8, this flaw represents a significant risk to the confidentiality, integrity, and availability of affected endpoints. Organizations should prioritize patching to prevent potential lateral movement or persistent access by malicious actors.
Remediation
Immediate Action: Update all instances of Microsoft Edge (Chromium-based) to version 153.0.4234.32 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected browser crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that endpoint protection solutions and browser-based security policies are active, and encourage users to remain vigilant against suspicious links or web-based content.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score of 8.8, this vulnerability poses a severe threat to enterprise environments. Security teams should treat this as a high-priority update task and ensure that the patch to version 153.0.4234.32 is deployed across all managed devices to neutralize the risk of privilege escalation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section