Use-after-free in Microsoft Edge - CVE-2026-66798
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute code.
The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) when rendering attacker-controlled web content. A remote attacker can host a malicious webpage and induce the victim to visit it to execute code.
User interaction is required, including visiting an attacker-controlled webpage and performing two tap gestures that cause autofill to activate.