CVE-2026-70341
massUse-After-Free RCE in Microsoft Edge (Chromium-based)
CVE-2026-70341 is a use-after-free memory-safety flaw (CWE-416) in Microsoft Edge's Chromium-based browser, rated 8.5 (High) with a network attack vector and high attack complexity. An authorized attacker — one who already holds some low level of privilege or access per the PR:L metric — can trigger the bug remotely with no user interaction required. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, and the changed-scope metric (S:C) indicates the impact can extend beyond the vulnerable component's normal security boundary. All deployments of Chromium-based Microsoft Edge that lack the fix are potentially affected; the available data does not specify affected or fixed build numbers. As of now the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so there is no confirmed active exploitation.
What to do: Update Microsoft Edge to the current stable-channel release incorporating the fix for this CVE as soon as Microsoft's advisory identifies the fixed build, and verify the update landed by checking edge://version. No workarounds are documented in the available data; since there is no known exploitation or public PoC, this can be handled within normal patch cycles, but the high CVSS score warrants prompt patching. Monitor Microsoft's advisory for the specific fixed version and any changes in exploitation status.
| Microsoft Edge (Chromium-based) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.