Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-88097

Опубликовано: 18 сент. 2026
Источник: msrc
CVSS3: 8.1
EPSS Низкий

Описание

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

For an attacker to exploit this vulnerability, they would need to have knowledge of a specific operation that triggers a memory allocation failure, specifically a use after free.

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An attacker could use this vulnerability to elevate privileges from a Low Integrity Level in a contained ("sandboxed") execution environment to a Medium Integrity Level. Please refer to AppContainer isolation and Mandatory Integrity Control for more information.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

This vulnerability could lead to a browser sandbox escape.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 13%
0.0022
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
5 дней назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

CVSS3: 8.1
github
5 дней назад

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

EPSS

Процентиль: 13%
0.0022
Низкий

8.1 High

CVSS3