ZeroHour

CVE-2026-70341

mass

Use-After-Free RCE in Microsoft Edge (Chromium-based)

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-70341 is a use-after-free memory-safety flaw (CWE-416) in Microsoft Edge's Chromium-based browser, rated 8.5 (High) with a network attack vector and high attack complexity. An authorized attacker — one who already holds some low level of privilege or access per the PR:L metric — can trigger the bug remotely with no user interaction required. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, and the changed-scope metric (S:C) indicates the impact can extend beyond the vulnerable component's normal security boundary. All deployments of Chromium-based Microsoft Edge that lack the fix are potentially affected; the available data does not specify affected or fixed build numbers. As of now the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no confirmed active exploitation.

What to do: Update Microsoft Edge to the current stable-channel release incorporating the fix for this CVE as soon as Microsoft's advisory identifies the fixed build, and verify the update landed by checking edge://version. No workarounds are documented in the available data; since there is no known exploitation or public PoC, this can be handled within normal patch cycles, but the high CVSS score warrants prompt patching. Monitor Microsoft's advisory for the specific fixed version and any changes in exploitation status.

Affected
Microsoft Edge (Chromium-based)
Estimated exposure
mass≈hundreds of millions of users/devices (Edge ships as the default browser on 1B+ Windows 10/11 devices) — Edge is preinstalled as the default browser on Windows 10 and 11, whose combined installed base exceeds one billion devices, and it holds a low-double-digit share of desktop browser usage, so the plausibly affected population is far above…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.