What is CWE-416?
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-416 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Memory-Unsafe; Language: C; Language: C++.
Source: MITRE CWE (CWE-416 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity — Modify Memory. The use of previously freed memory may corrupt valid data, if the memory area in question has been allocated and used properly elsewhere.
- Availability — DoS: Crash, Exit, or Restart. If chunk consolidation occurs after the use of previously freed data, the process may crash when invalid data is used as chunk information.
- Integrity, Confidentiality, Availability — Execute Unauthorized Code or Commands. If malicious data is entered before chunk consolidation can take place, it may be possible to take advantage of a write-what-where primitive to execute arbitrary code. If the newly allocated data happens to hold a class, in C++ for example, various function pointers may be scattered within the heap data. If one of these function pointers is overwritten with an address to valid shellcode, execution of arbitrary code can be achieved.
Source: MITRE CWE, common consequences.
How CWE-416 is exploited in the wild
Threadlinqs maps 95 CVEs to CWE-416, published between 2010-01-15 and 2026-09-29. 18 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 4 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 18 critical, 61 high, 7 medium, 2 low. The highest EPSS score in the set is 99.9% (CVE-2019-0708), the modelled probability of exploitation in the next 30 days. 92 tracked threats reference CWE-416 directly or through a CVE it covers; the most recent is “Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)” (2026-10-02). Affected products concentrate in Google (41), Microsoft (27), Apple (8), among 31 vendors in total.
Vulnerabilities (CVEs)
Showing 40 of 95 CVEs mapped to CWE-416, CISA KEV first, then by CVSS score.
- CVE-2019-0708 — CISA KEV · CVSS 9.8 critical · EPSS 99.9% · published 2019-05-16
- CVE-2024-9680 — CISA KEV · CVSS 9.8 critical · EPSS 30.8% · published 2024-10-09
- CVE-2026-34621 — CISA KEV · CVSS 9.8 critical · EPSS 9.8% · published 2026-04-13
- CVE-2021-37973 — CISA KEV · CVSS 9.6 critical · EPSS 6.4% · published 2021-10-08
- CVE-2010-0249 — CISA KEV · CVSS 8.8 high · EPSS 88.7% · published 2010-01-15
- CVE-2010-0806 — CISA KEV · CVSS 8.8 high · EPSS 87.2% · published 2010-03-10
- CVE-2026-5281 — CISA KEV · CVSS 8.8 high · EPSS 3.2% · published 2026-04-01
- CVE-2026-2441 — CISA KEV · CVSS 8.8 high · EPSS 0.2% · published 2026-02-13
- CVE-2025-43529 — CISA KEV · CVSS 8.8 high · EPSS 0.1% · published 2025-12-17
- CVE-2023-43000 — CISA KEV · CVSS 8.8 high · EPSS 0.0% · published 2025-11-05
- CVE-2023-32373 — CISA KEV · CVSS 8.8 high · EPSS 0.0% · published 2023-06-23
- CVE-2021-1048 — CISA KEV · CVSS 7.8 high · EPSS 1.2% · published 2021-12-15
- CVE-2024-43047 — CISA KEV · CVSS 7.8 high · EPSS 0.6% · published 2024-10-07
- CVE-2024-4610 — CISA KEV · CVSS 7.8 high · EPSS 0.5% · published 2024-06-07
- CVE-2023-41974 — CISA KEV · CVSS 7.8 high · EPSS 0.1% · published 2024-01-10
- CVE-2025-48543 — CISA KEV · CVSS 7.5 high · EPSS 0.3% · published 2025-09-04
- CVE-2026-68820 — CISA KEV · CVSS 7 high · EPSS 0.3% · published 2026-08-11
- CVE-2022-2586 — CISA KEV · CVSS 5.3 medium · EPSS 10.4% · published 2024-01-08
- CVE-2025-49844 — CVSS 10 critical · EPSS 11.1% · published 2025-10-03
- CVE-2026-57092 — CVSS 9.9 critical · published 2026-07-14
- CVE-2020-28951 — CVSS 9.8 critical · EPSS 1.7% · published 2020-11-19
- CVE-2026-69525 — CVSS 9.8 critical · EPSS 0.9% · published 2026-09-08
- CVE-2026-69730 — CVSS 9.8 critical · EPSS 0.9% · published 2026-09-08
- CVE-2026-81934 — CVSS 9.8 critical · EPSS 0.5% · published 2026-08-27
- CVE-2026-45185 — CVSS 9.8 critical · EPSS 0.0% · published 2026-05-12
- CVE-2026-87464 — CVSS 9.6 critical · EPSS 0.5% · published 2026-09-09
- CVE-2026-12440 — CVSS 9.6 critical · EPSS 0.3% · published 2026-06-17
- CVE-2026-14425 — CVSS 9.6 critical · EPSS 0.2% · published 2026-07-01
- CVE-2026-14417 — CVSS 9.6 critical · EPSS 0.1% · published 2026-07-01
- CVE-2026-16424 — CVSS 9.6 critical · EPSS 0.1% · published 2026-07-21
- CVE-2026-102306 — CVSS 9.6 critical · published 2026-09-29
- CVE-2026-40402 — CVSS 9.3 critical · EPSS 0.0% · published 2026-05-12
- CVE-2026-42985 — CVSS 8.8 high · EPSS 0.9% · published 2026-06-09
- CVE-2026-85893 — CVSS 8.8 high · EPSS 0.6% · published 2026-09-15
- CVE-2026-10882 — CVSS 8.8 high · EPSS 0.4% · published 2026-06-04
- CVE-2026-16806 — CVSS 8.8 high · EPSS 0.4% · published 2026-07-23
- CVE-2026-12442 — CVSS 8.8 high · EPSS 0.3% · published 2026-06-17
- CVE-2026-16805 — CVSS 8.8 high · EPSS 0.3% · published 2026-07-23
- CVE-2026-12439 — CVSS 8.8 high · EPSS 0.3% · published 2026-06-17
- CVE-2026-12441 — CVSS 8.8 high · EPSS 0.2% · published 2026-06-17
Affected vendors
Threat activity
92 tracked threats cite CWE-416; the 25 most recent are listed.
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)CRITICAL
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60MEDIUM
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)CRITICAL
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)MEDIUM
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and DCSync to Compromise Russian Active DirectoryCRITICAL
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)CRITICAL
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense IndustryCRITICAL
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV CatalogCRITICAL
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)HIGH
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEsCRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student ProtestersHIGH
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked ActorsHIGH
- Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)CRITICAL
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack AnotherCRITICAL
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege EscalationHIGH
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical FlawsCRITICAL
- "When Agentic Glue Melts": Five workerd Memory-Corruption Flaws Enable Cross-Tenant Secret Theft and Code Mode Sandbox Escape on Cloudflare WorkersCRITICAL
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)HIGH
- Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150, Including 13-Year-Old ANGLE Sandbox-Escape (CVE-2026-10881)
- Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape / Local-Privilege-Escalation Bugs (CVE-2026-17650 – CVE-2026-17656)CRITICAL
- CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege EscalationHIGH
- Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)HIGH
Mitigations
- Architecture and Design / Language Selection: Choose a language that provides automatic memory management.
- Implementation / Attack Surface Reduction: When freeing pointers, be sure to set them to NULL once they are freed. However, the utilization of multiple or complex data structures may lower the usefulness of this strategy.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Fuzzing (effectiveness: High): Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with random inputs, it is often capable of generating unexpected results such as crashes, memory corruption, or resource consumption. Fuzzing effectively produces repeatable test cases that clearly indicate bugs, which helps developers to diagnose the issues.
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
- Automated Dynamic Analysis (effectiveness: Moderate): Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518].
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.