CVE-2026-88097: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Other sources
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.46
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be able to act locally on the affected system. The CVSS vector indicates no prior privileges or user interaction are required, but exploitation has high attack complexity.
What could an attacker gain if exploitation succeeds?
Successful exploitation can elevate the attacker’s privileges. The CVSS assessment also rates confidentiality, integrity, and availability impact as high, with scope changed.
Is there evidence of public exploitation?
The CVSS vector lists exploit code maturity as unproven (E:U). The provided data does not identify publicly available exploit code or confirmed exploitation.