cbcvebase.

Microsoft Edge Chromium vulnerabilities

258 known vulnerabilities affecting microsoft/edge_chromium.

Total CVEs
258
CISA KEV
9
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL13HIGH128MEDIUM110LOW7

Vulnerabilities

Page 1 of 13
CVE-2023-4863P1HIGHCVSS 8.8KEVPoCfixed in 116.0.1938.812023-09-12
CVE-2023-4863 [HIGH] CWE-787 CVE-2023-4863: Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2023-5217P1HIGHCVSS 8.8KEVPoCv116.0.5845.229v117.0.5938.1322023-09-28
CVE-2023-5217 [HIGH] CWE-787 CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-14174P1HIGHCVSS 8.8KEVPoCfixed in 143.0.3650.802025-12-12
CVE-2025-14174 [HIGH] CWE-787 CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remot Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4762P1HIGHCVSS 8.8KEVPoCfixed in 116.0.1938.762023-09-05
CVE-2023-4762 [HIGH] CWE-843 CVE-2023-4762: Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute a Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7965P1HIGHCVSS 8.8KEVPoCfixed in 128.0.2739.422024-08-21
CVE-2024-7965 [HIGH] CWE-787 CVE-2024-7965: Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-5419P1HIGHCVSS 8.8KEVPoCfixed in 137.0.3296.622025-06-03
CVE-2025-5419 [HIGH] CWE-125 CVE-2025-5419: Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-16009P1HIGHCVSS 8.8KEVfixed in 86.0.4240.1832020-11-03
CVE-2020-16009 [HIGH] CWE-787 CVE-2020-16009: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4135P1CRITICALCVSS 9.6KEVfixed in 107.0.5304.1502022-11-25
CVE-2022-4135 [CRITICAL] CWE-787 CVE-2022-4135: Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who h Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6345P1CRITICALCVSS 9.6KEVfixed in 119.0.2151.972023-11-29
CVE-2023-6345 [CRITICAL] CWE-190 CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2025-49741P2HIGHCVSS 7.5PoCfixed in 135.0.3179.982025-07-01
CVE-2025-49741 [HIGH] CWE-268 CVE-2025-49741: No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-6702P2HIGHCVSS 8.8fixed in 120.0.2210.772023-12-14
CVE-2023-6702 [HIGH] CWE-843 CVE-2023-6702: Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potential Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-24892P3HIGHCVSS 8.2PoCfixed in 111.0.1661.412023-03-14
CVE-2023-24892 [HIGH] CWE-601 CVE-2023-24892: Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
nvd
CVE-2023-33145P3MEDIUMCVSS 6.5PoCfixed in 114.0.1823.512023-06-14
CVE-2023-33145 [MEDIUM] CVE-2023-33145: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
nvd
CVE-2026-45495P2CRITICALCVSS 9.8fixed in 148.0.3967.702026-05-18
CVE-2026-45495 [CRITICAL] CWE-35 CVE-2026-45495: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2026-57983P2CRITICALCVSS 10.0fixed in 150.0.4078.482026-07-03
CVE-2026-57983 [CRITICAL] CWE-285 CVE-2026-57983: Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2021-21132P2CRITICALCVSS 9.6fixed in 88.0.705.502021-02-09
CVE-2021-21132 [CRITICAL] CWE-1021 CVE-2021-21132: Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote att Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2024-43566P2CRITICALCVSS 9.8fixed in 130.0.2849.462024-10-17
CVE-2024-43566 [CRITICAL] CWE-190 CVE-2024-43566: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2021-21118P3HIGHCVSS 8.8fixed in 88.0.705.502021-02-09
CVE-2021-21118 [HIGH] CWE-119 CVE-2021-21118: Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2024-38219P3CRITICALCVSS 9.0fixed in 127.0.2651.982024-08-12
CVE-2024-38219 [CRITICAL] CWE-843 CVE-2024-38219: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2021-21121P3CRITICALCVSS 9.6fixed in 88.0.705.502021-02-09
CVE-2021-21121 [CRITICAL] CWE-416 CVE-2021-21121: Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
1 / 13Next →
Microsoft Edge Chromium vulnerabilities | cvebase