Use-after-free in Microsoft Edge - CVE-2026-85893
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to elevate privileges.
The vulnerability exists due to use-after-free in Microsoft Edge (Chromium-based) autofill functionality when activating autofill on an attacker-controlled webpage. A remote attacker can cause the user to visit an attacker-controlled webpage and perform two tap gestures that activate autofill to elevate privileges.
Successful exploitation elevates privileges from a low-integrity sandboxed execution environment to a medium-integrity level.