CVE-2026-69486: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Sep 15, 2026
·Updated
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft Microsoft Edge
Microsoft Edge (Chromium-based)<153.0.4234.32
153.0.4234.32
Microsoft Edge<153.0.4234.32
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32
Event History
Sep 15, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
DescriptionAffected Software
CVE Published
via MITRE·10:39 PM
Data Sourced
via MITRE·10:39 PM
DescriptionSeverity
Frequently Asked Questions
1
What attacker interaction is required for exploitation?
The vector indicates network-based exploitation with low attack complexity and no privileges required, but user interaction is required.
2
What impact could successful exploitation have?
Successful exploitation could allow code execution and has high potential impact on confidentiality, integrity, and availability.
3
Which products are identified as affected?
The provided data identifies Microsoft Edge, including Microsoft Edge (Chromium-based), as affected.