HIGH 8.3

CVE-2026-58287: Microsoft Edge Use-After-Free RCE Vulnerability (CVSS 8.3)

Microsoft Edge (Chromium-based) contains a use-after-free memory vulnerability that allows attackers to execute arbitrary code on a user's system. The flaw requires user interaction—such as visiting a malicious website or opening a crafted file—but once triggered, it can lead to complete system compromise. The vulnerability carries a HIGH severity rating and affects the integrity, confidentiality, and availability of affected systems.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.3 HIGH · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-416
Affected products
1 configuration(s)
Published / Modified
2026-07-03 / 2026-07-07

NVD description (verbatim)

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-58287 is a use-after-free vulnerability (CWE-416) in Microsoft Edge's Chromium engine. Use-after-free flaws occur when a program references memory that has been deallocated, allowing attackers to manipulate freed memory to execute arbitrary code. The vulnerability is reachable over the network and requires user interaction (UI:R) but has low attack complexity (AC:H), suggesting exploitation is technically feasible but may depend on specific conditions or browser state. The attack vector is network-based (AV:N), and the impact scope is changed (S:C), meaning compromise can extend beyond the vulnerable component.

Business impact

Successful exploitation could allow attackers to remotely execute code with the privileges of the user running Microsoft Edge. This enables theft of sensitive data, installation of persistent malware, lateral movement within corporate networks, and disruption of business operations. Organizations with BYOD policies or those relying on Edge for business-critical applications face elevated risk. The requirement for user interaction slightly reduces—but does not eliminate—organizational risk, as social engineering and drive-by downloads remain effective attack vectors.

Affected systems

Microsoft Edge (Chromium-based) is affected. Organizations using Microsoft Edge in enterprise environments, particularly those deployed via Windows Update or Windows Server Update Services (WSUS), should identify and inventory affected instances. Chromium-based variants of Edge across Windows, macOS, and Linux platforms should be considered in scope for assessment.

Exploitability

The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating no widespread active exploitation has been reported or confirmed as of the publication date. However, the combination of network accessibility, user interaction requirement, and remote code execution capability suggests that reliable exploits could be developed. Users and administrators should treat this as a credible exploitation risk and prioritize patching.

Remediation

Apply security updates from Microsoft for Microsoft Edge (Chromium-based) as soon as they become available. Monitor the Microsoft Edge release notes and security advisories for patch version numbers and deployment guidance. In the interim, consider restricting Edge usage where possible, disabling problematic extensions, and educating users about the risks of visiting untrusted websites or opening unexpected files.

Patch guidance

Consult Microsoft's official security advisories and the Microsoft Edge release notes for the specific patch version that addresses CVE-2026-58287. Verify patch applicability to your deployed Edge versions—updates may be released through Windows Update, the Microsoft Edge auto-update mechanism, or manual download from microsoft.com. Test patches in a non-production environment before broad rollout. For enterprise deployments, use group policy or mobile device management (MDM) to enforce timely patching across the organization.

Detection guidance

Monitor for crashes or unexpected behavior in Microsoft Edge processes, particularly those involving memory corruption or suspicious code execution. Endpoint Detection and Response (EDR) solutions should be configured to flag use-after-free-style memory violations and browser-based code execution attempts. Web traffic inspection can identify known malicious domains or files associated with exploitation campaigns. Consider enabling browser crash reporting to Microsoft to aid in detection of active exploitation attempts.

Why prioritize this

Although not currently in the KEV catalog, this vulnerability merits rapid patching due to its HIGH CVSS score (8.3), remote exploitability, potential for remote code execution, and wide user base of Microsoft Edge. The user-interaction requirement slightly lowers urgency compared to zero-interaction flaws, but should not delay patching beyond standard security update windows.

Risk score, explained

The CVSS 3.1 score of 8.3 reflects the combination of network attack vector, high impact on confidentiality and integrity, changed scope, and user-interaction requirement. The score appropriately weights the severity of remote code execution against the barrier of requiring user interaction. This score positions the vulnerability as HIGH severity and a strong candidate for prioritization in patch management workflows.

Frequently asked questions

Is there a public exploit for CVE-2026-58287?

As of the publication date, this vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, and no widely available public exploit has been reported. However, organizations should not rely on obscurity; patching should proceed without delay.

Do all versions of Microsoft Edge need to be patched?

The vulnerability affects Microsoft Edge (Chromium-based). Verify your deployed version against Microsoft's security advisory to confirm which versions are vulnerable and which patches are required. Legacy Edge (pre-Chromium) is not affected.

Can this vulnerability be exploited without user interaction?

No. The vulnerability requires user interaction, typically visiting a malicious website or opening a crafted file. However, this should not be underestimated as a protective factor—social engineering and drive-by download campaigns remain highly effective.

What should organizations do immediately?

Inventory Microsoft Edge deployments, verify patch availability from Microsoft, test patches in a test environment, and plan a phased rollout to production systems. In parallel, reinforce user security awareness regarding untrusted links and files.

This analysis is based on publicly available information as of the publication date (2026-07-03). Patch availability, exploit details, and threat activity may evolve. Organizations should verify all recommendations, including patch versions and deployment procedures, against official vendor advisories before implementation. SEC.co makes no warranty regarding the completeness or accuracy of vulnerability details and accepts no liability for actions taken in reliance on this intelligence. Always consult vendor advisories for authoritative guidance. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).