🟠 High  |  Source: Microsoft Security Response Center


A use-after-free vulnerability in WebGL (CVE-2026-13028) has been identified in the Chromium engine, affecting Microsoft Edge and other Chromium-based browsers. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating memory after it has been freed. Microsoft Edge will receive a fix by ingesting the upstream Chromium patch addressed by Google.

Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual machines, including Azure Virtual Desktop environments. Prioritise patch deployment via Intune or your endpoint management tooling, and consider enforcing browser version compliance policies to reduce exposure windows.

Original advisory: Chromium: CVE-2026-13028 Use after free in WebGL