🟠 High | Source: Microsoft Security Response Center
CVE-2026-16804 is a use-after-free vulnerability in the Input component of the Chromium browser engine, which underpins Microsoft Edge. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, potentially compromising a user’s system if they visit a malicious page. Microsoft Edge will receive a patch via its regular Chromium ingestion process.
Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints as soon as the patched build is available; enforce browser update policies via Intune or Group Policy and consider blocking unmanaged Edge installs on corporate devices until the fix is confirmed deployed.
Original advisory: Chromium: CVE-2026-16804 Use after free in Input