🟠 High  |  Source: Microsoft Security Response Center


A use-after-free vulnerability (CVE-2026-16806) has been identified in the WebMCP component of Chromium, which underpins Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. This affects any environment where Microsoft Edge is deployed, including cloud-connected workstations and virtual desktop infrastructure.

Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-based release as soon as it becomes available via your patch management tooling; prioritise endpoints and VDI images that access sensitive cloud management portals or Azure services, as browser-based code execution could facilitate credential theft or session hijacking.

Original advisory: Chromium: CVE-2026-16806 Use after free in WebMCP