cbcvebase.

Microsoft Edge Chromium vulnerabilities

258 known vulnerabilities affecting microsoft/edge_chromium.

Total CVEs
258
CISA KEV
9
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL13HIGH128MEDIUM110LOW7

Vulnerabilities

Page 3 of 13
CVE-2023-35618P3CRITICALCVSS 9.6fixed in 120.0.2210.612023-12-07
CVE-2023-35618 [CRITICAL] CWE-416 CVE-2023-35618: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2025-25000P3HIGHCVSS 8.8fixed in 135.0.3179.542025-04-04
CVE-2025-25000 [HIGH] CWE-843 CVE-2025-25000: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43489P3HIGHCVSS 8.8fixed in 129.0.2792.522024-09-19
CVE-2024-43489 [HIGH] CWE-843 CVE-2024-43489: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2025-49713P3HIGHCVSS 8.8fixed in 138.0.3351.652025-07-02
CVE-2025-49713 [HIGH] CWE-843 CVE-2025-49713: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58281P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-11
CVE-2026-58281 [HIGH] CWE-502 CVE-2026-58281: Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58289P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-03
CVE-2026-58289 [HIGH] CWE-843 CVE-2026-58289: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-36735P3CRITICALCVSS 9.6fixed in 117.0.2045.312023-09-15
CVE-2023-36735 [CRITICAL] CWE-416 CVE-2023-36735: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2021-21127P3HIGHCVSS 8.8fixed in 88.0.705.502021-02-09
CVE-2021-21127 [HIGH] CVE-2021-21127: Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remot Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.
nvd
CVE-2026-58287P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-03
CVE-2026-58287 [HIGH] CWE-416 CVE-2026-58287: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58285P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-03
CVE-2026-58285 [HIGH] CWE-843 CVE-2026-58285: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58288P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-03
CVE-2026-58288 [HIGH] CWE-416 CVE-2026-58288: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43587P3HIGHCVSS 8.1fixed in 130.0.2849.462024-10-17
CVE-2024-43587 [HIGH] CWE-122 CVE-2024-43587: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2026-58295P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-03
CVE-2026-58295 [HIGH] CWE-843 CVE-2026-58295: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2024-21326P3CRITICALCVSS 9.6fixed in 121.0.2277.832024-01-26
CVE-2024-21326 [CRITICAL] CWE-416 CVE-2024-21326: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2021-38669P3HIGHCVSS 8.8fixed in 93.04577.632021-09-15
CVE-2021-38669 [HIGH] CVE-2021-38669: Microsoft Edge (Chromium-based) Tampering Vulnerability Microsoft Edge (Chromium-based) Tampering Vulnerability
nvd
CVE-2021-21125P3HIGHCVSS 8.1fixed in 88.0.705.502021-02-09
CVE-2021-21125 [HIGH] CWE-59 CVE-2021-21125: Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2023-36787P3HIGHCVSS 8.8fixed in 116.0.1938.542023-08-21
CVE-2023-36787 [HIGH] CWE-416 CVE-2023-36787: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2022-22021P3HIGHCVSS 8.3fixed in 102.0.1245.392022-06-15
CVE-2022-22021 [HIGH] CVE-2022-22021: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-43579P3HIGHCVSS 8.3fixed in 130.0.2849.462024-10-17
CVE-2024-43579 [HIGH] CWE-122 CVE-2024-43579: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-43578P3HIGHCVSS 8.3fixed in 130.0.2849.462024-10-17
CVE-2024-43578 [HIGH] CWE-122 CVE-2024-43578: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
Microsoft Edge Chromium vulnerabilities | cvebase