CVE-2026-70341: Use-after-free in Microsoft Edge (Chromium-based) Allows Remote Code Execution
A NVD · · CVE-2026-70341
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- CVSS
- 8.5
- EPSS
- 0%
Key insight
No additional strategic information beyond patch announcement available; merely technical CVE classification without context of active exploits or campaigns.
Description
CVE-2026-70341 describes a use-after-free vulnerability in the Chromium-based Microsoft Edge browser. The vulnerability enables an authenticated attacker to execute code over the network. It affects browser processes and could be triggered through malicious web content or deliberately crafted network traffic. To date, no public reports of active exploitation have emerged; the CVE number suggests a future or already-patched vulnerability.
Risk score
- cvss base
- 85.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 85.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational
MITRE ATT&CK mapping
1 TTPProcedure details
| Technique | Tactic | Procedure | Conf. | Source |
|---|---|---|---|---|
| T1203 Exploitation for Client Execution | Execution | The attacker exploits a use-after-free vulnerability in Microsoft Edge (Chromium-based) to execute arbitrary code on the victim's system when the victim visits a malicious web page or opens crafted content. | high | llm |