Skip to content
Auto-CTI
Back to today
NEW CRITICAL A2

CVE-2026-70341: Use-after-free in Microsoft Edge (Chromium-based) Allows Remote Code Execution

A NVD · · CVE-2026-70341

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
8.5
EPSS
0%

Key insight

No additional strategic information beyond patch announcement available; merely technical CVE classification without context of active exploits or campaigns.

Description

CVE-2026-70341 describes a use-after-free vulnerability in the Chromium-based Microsoft Edge browser. The vulnerability enables an authenticated attacker to execute code over the network. It affects browser processes and could be triggered through malicious web content or deliberately crafted network traffic. To date, no public reports of active exploitation have emerged; the CVE number suggests a future or already-patched vulnerability.

Risk score

100
cvss base
85.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
85.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

MITRE ATT&CK mapping

1 TTP
Recon
Resource Dev
Initial Access
Persistence
Priv. Escal.
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1203
Exploitation for Client Execution
Execution The attacker exploits a use-after-free vulnerability in Microsoft Edge (Chromium-based) to execute arbitrary code on the victim's system when the victim visits a malicious web page or opens crafted content. high llm
ESC