Use-after-free in Microsoft Edge - CVE-2026-70341

 

Use-after-free in Microsoft Edge - CVE-2026-70341

Published: August 31, 2026


Vulnerability identifier: #VU146313
CSH Severity: Medium
CVSS v4: 7.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70341
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) when processing specially crafted web content. A remote user can trigger specially crafted activity in the affected browser process to execute arbitrary code.

Successful exploitation requires existing ability to execute JavaScript in the affected Microsoft Edge process and can lead to code execution beyond the browser's security scope.


Affected software

Microsoft Edge

How to mitigate CVE-2026-70341

Install security update from vendor's website.

Microsoft Edge - update to 152.0.4191.53

External References

Related Security Bulletins