Use-after-free in Microsoft Edge - CVE-2026-70341
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) when processing specially crafted web content. A remote user can trigger specially crafted activity in the affected browser process to execute arbitrary code.
Successful exploitation requires existing ability to execute JavaScript in the affected Microsoft Edge process and can lead to code execution beyond the browser's security scope.