Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-66312 Published on August 3, 2026

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Vendor Advisory NVD

Weakness Type

Buffer Over-read

The software reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. This typically occurs when the pointer or its index is incremented to a position beyond the bounds of the buffer or when pointer arithmetic results in a position outside of the valid memory location to name a few. This may result in exposure of sensitive information or possibly a crash.


Products Associated with CVE-2026-66312

Want to know whenever a new CVE is published for Microsoft Edge Chromium? stack.watch will email you.

 

Affected Versions

Microsoft Edge (Chromium-based):