Use-after-free in Microsoft Edge - CVE-2026-57981
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a specially crafted website and convince the user to visit it to execute arbitrary code.
User interaction is required, and exploitation requires the user to visit the attacker-controlled webpage and perform two tap gestures that cause autofill to activate.