CVE-2026-88097

8.1

Microsoft · Microsoft Edge (Chromium-based)

A use after free vulnerability in Microsoft Edge (Chromium-based) allows an unauthorized attacker to achieve local privilege escalation.

Executive summary

A use after free vulnerability in Microsoft Edge (Chromium-based) could allow an unauthorized attacker to gain elevated privileges on the host system.

Vulnerability

This vulnerability is a use after free condition that occurs when memory is accessed after it has been freed. The vulnerability is exploitable by an unauthorized attacker with local access to the system.

Business impact

The ability for an unauthorized user to escalate privileges locally poses a significant risk to the confidentiality, integrity, and availability of the affected system. With a CVSS score of 8.1, this high-severity vulnerability could allow an attacker to bypass security controls, potentially leading to a full system compromise or unauthorized access to sensitive data.

Remediation

Immediate Action: Update Microsoft Edge (Chromium-based) to version 153.0.4234.46 or later as specified in the Microsoft security update guide.

Proactive Monitoring: Monitor local system logs for unusual process activity or unauthorized attempts to access restricted files that might indicate an exploitation attempt.

Compensating Controls: Ensure endpoint security software is configured to detect and block malicious memory manipulation patterns, which can provide a layer of defense while the update is being deployed.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for complete system compromise through local privilege escalation, organizations should prioritize the deployment of the vendor-provided patch to all workstations and servers running the affected version of Microsoft Edge. Regular patching cycles for browser software are essential to mitigating risks associated with memory corruption vulnerabilities.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources