CVE-2026-21223
published 2026-01-16CVE-2026-21223: Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
PriorityP336high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.25%
16.5th percentile
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 144.0.3719.82 | 144.0.3719.82 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 144.0.3719.82 | 144.0.3719.82 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
vendor_msrc·2026-01-13·CVSS 7.1
CVE-2026-21223 [HIGH] CWE-269 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Description: Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An authenticated local attacker can disable or enable Windows VBS without administrative privileges, resulting in bypass of platform security hardening. This does not grant direct code execution as another user but weakens system security guarantees, enabling follow‑on attacks.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
144.0.3719.82
01/16/2026
144.0.7559.60
FAQ: According to the CVSS metrics, suc
GHSA
GHSA-wfh6-52w8-8gcj: Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process
ghsa_unreviewed·2026-01-17
CVE-2026-21223 [MEDIUM] CWE-269 GHSA-wfh6-52w8-8gcj: Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process
Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem.
This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass.
No detection rules found.
No public exploits indexed.
2026-01-16
Published