Microsoft Edge Chromium vulnerabilities
205 known vulnerabilities affecting microsoft/edge_chromium.
Total CVEs
205
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
7
Severity breakdown
CRITICAL11HIGH97MEDIUM90LOW7
Vulnerabilities
Page 1 of 11
CVE-2026-0385MEDIUMCVSS 5.0fixed in 146.0.3856.592026-03-16
CVE-2026-0385 [MEDIUM] CWE-451 CVE-2026-0385: Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
nvd
CVE-2026-0102LOWCVSS 3.1fixed in 145.0.3800.582026-02-17
CVE-2026-0102 [LOW] CWE-359 CVE-2026-0102: Under specific conditions, a malicious webpage may trigger autofill population after two consecutive
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
nvd
CVE-2026-21223HIGHCVSS 7.1fixed in 144.0.3719.822026-01-16
CVE-2026-21223 [HIGH] CWE-269 CVE-2026-21223: Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to by
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-65046LOWCVSS 3.1fixed in 143.0.3650.882025-12-18
CVE-2025-65046 [LOW] CWE-451 CVE-2025-65046: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2025-14174HIGHCVSS 8.8KEVfixed in 143.0.3650.802025-12-12
CVE-2025-14174 [HIGH] CWE-787 CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remot
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-60711MEDIUMCVSS 6.3fixed in 142.0.3595.532025-10-31
CVE-2025-60711 [MEDIUM] CWE-693 CVE-2025-60711: Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to e
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-59251HIGHCVSS 7.6fixed in 140.0.3485.812025-09-24
CVE-2025-59251 [HIGH] CWE-121 CVE-2025-59251: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2025-53791MEDIUMCVSS 4.7fixed in 140.0.3485.542025-09-05
CVE-2025-53791 [MEDIUM] CWE-284 CVE-2025-53791: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-47182MEDIUMCVSS 5.6fixed in 138.0.3351.552025-07-11
CVE-2025-47182 [MEDIUM] CWE-20 CVE-2025-47182: Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-47963MEDIUMCVSS 6.5fixed in 138.0.3351.552025-07-11
CVE-2025-47963 [MEDIUM] CWE-451 CVE-2025-47963: No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-47964MEDIUMCVSS 4.3fixed in 138.0.3351.552025-07-11
CVE-2025-47964 [MEDIUM] CWE-451 CVE-2025-47964: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2025-49713HIGHCVSS 8.8fixed in 138.0.3351.652025-07-02
CVE-2025-49713 [HIGH] CWE-843 CVE-2025-49713: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49741HIGHCVSS 7.5PoCfixed in 135.0.3179.982025-07-01
CVE-2025-49741 [HIGH] CWE-268 CVE-2025-49741: No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-5419HIGHCVSS 8.8KEVfixed in 137.0.3296.622025-06-03
CVE-2025-5419 [HIGH] CWE-125 CVE-2025-5419: Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-29834HIGHCVSS 7.5fixed in 134.0.3124.932025-04-12
CVE-2025-29834 [HIGH] CWE-125 CVE-2025-29834: Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute cod
Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-25000HIGHCVSS 8.8fixed in 135.0.3179.542025-04-04
CVE-2025-25000 [HIGH] CWE-843 CVE-2025-25000: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29815HIGHCVSS 7.6fixed in 134.0.3124.662025-04-04
CVE-2025-29815 [HIGH] CWE-416 CVE-2025-29815: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
nvd
CVE-2025-29806MEDIUMCVSS 6.5fixed in 129.0.2792.522025-03-23
CVE-2025-29806 [MEDIUM] CWE-843 CVE-2025-29806: No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-26643MEDIUMCVSS 5.4fixed in 134.0.3124.512025-03-07
CVE-2025-26643 [MEDIUM] CWE-449 CVE-2025-26643: The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-21401MEDIUMCVSS 4.5fixed in 133.0.3065.692025-02-15
CVE-2025-21401 [MEDIUM] CWE-601 CVE-2025-21401: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
1 / 11Next →