CVE-2026-32187
published 2026-03-27CVE-2026-32187: Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
PriorityP418medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge | < 146.0.3856.84 | 146.0.3856.84 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 146.0.3856.84 | 146.0.3856.84 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
cvelistv54.2MEDIUM
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
vendor_msrc·2026-03-10·CVSS 4.2
CVE-2026-32187 [MEDIUM] Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to manipulate system operations in a specific manner.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H), and some loss of integrity (I:L), but no loss of availability (A:N). What does that mean for this vulnerability?
An attacker who successfully exploited this vulnerability could view sensitive information, (Confidentiality), and make some changes to disclosed information (Integrity), but they would not be able to affect Availability.
FAQ: According to the CVSS m
CVEList
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
cvelistv5·2026-03-27·CVSS 4.2
CVE-2026-32187 [MEDIUM] Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
GHSA
GHSA-ppf8-9fmv-q7vm: Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
ghsa_unreviewed·2026-03-27
CVE-2026-32187 [MEDIUM] CWE-1021 GHSA-ppf8-9fmv-q7vm: Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
No detection rules found.
No public exploits indexed.
2026-03-27
Published