A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
https://www.zerodayinitiative.com/advisories/ZDI-20-698/
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1219