Microsoft Edge Chromium vulnerabilities
258 known vulnerabilities affecting microsoft/edge_chromium.
Total CVEs
258
CISA KEV
9
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL13HIGH128MEDIUM110LOW7
Vulnerabilities
Page 2 of 13
CVE-2026-57985P3HIGHCVSS 8.8fixed in 150.0.4078.482026-07-03
CVE-2026-57985 [HIGH] CWE-20 CVE-2026-57985: Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exec
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50521P3HIGHCVSS 8.3fixed in 149.0.4022.672026-07-01
CVE-2026-50521 [HIGH] CWE-416 CVE-2026-50521: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-57981P3HIGHCVSS 8.8fixed in 150.0.4078.482026-07-03
CVE-2026-57981 [HIGH] CWE-416 CVE-2026-57981: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-21124P3CRITICALCVSS 9.6fixed in 88.0.705.502021-02-09
CVE-2021-21124 [CRITICAL] CWE-416 CVE-2021-21124: Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 all
Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2024-21388P3MEDIUMCVSS 6.5fixed in 121.0.2277.832024-01-30
CVE-2024-21388 [MEDIUM] CWE-20 CVE-2024-21388: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2025-21279P3HIGHCVSS 8.8fixed in 133.0.3065.512025-02-06
CVE-2025-21279 [HIGH] CWE-843 CVE-2025-21279: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2026-56645P3HIGHCVSS 8.8fixed in 150.0.4078.482026-07-03
CVE-2026-56645 [HIGH] CWE-122 CVE-2026-56645: Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-21157P3HIGHCVSS 8.8fixed in 88.0.4324.1822021-02-22
CVE-2021-21157 [HIGH] CWE-416 CVE-2021-21157: Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote atta
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2025-21283P3HIGHCVSS 8.8fixed in 133.0.3065.512025-02-06
CVE-2025-21283 [HIGH] CWE-1222 CVE-2025-21283: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2025-21408P3HIGHCVSS 8.8fixed in 133.0.3065.512025-02-06
CVE-2025-21408 [HIGH] CWE-843 CVE-2025-21408: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2025-21342P3HIGHCVSS 8.8fixed in 133.0.3065.512025-02-06
CVE-2025-21342 [HIGH] CWE-843 CVE-2025-21342: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2021-21122P3HIGHCVSS 8.8fixed in 88.0.705.502021-02-09
CVE-2021-21122 [HIGH] CWE-416 CVE-2021-21122: Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentia
Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2024-43596P3HIGHCVSS 8.8fixed in 130.0.2849.462024-10-17
CVE-2024-43596 [HIGH] CWE-843 CVE-2024-43596: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-43595P3HIGHCVSS 8.8fixed in 130.0.2849.462024-10-17
CVE-2024-43595 [HIGH] CWE-126 CVE-2024-43595: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-43496P3HIGHCVSS 8.8fixed in 129.0.2792.522024-09-19
CVE-2024-43496 [HIGH] CWE-787 CVE-2024-43496: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2021-21120P3HIGHCVSS 8.8fixed in 88.0.705.502021-02-09
CVE-2021-21120 [HIGH] CWE-416 CVE-2021-21120: Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potenti
Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21119P3HIGHCVSS 8.8fixed in 88.0.705.502021-02-09
CVE-2021-21119 [HIGH] CWE-416 CVE-2021-21119: Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had com
Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-57974P3HIGHCVSS 8.8fixed in 150.0.4078.482026-07-03
CVE-2026-57974 [HIGH] CWE-190 CVE-2026-57974: Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-21128P3HIGHCVSS 8.8fixed in 88.0.705.502021-02-09
CVE-2021-21128 [HIGH] CWE-787 CVE-2021-21128: Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to po
Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-58284P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-03
CVE-2026-58284 [HIGH] CWE-285 CVE-2026-58284: Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd