Microsoft Edge Chromium vulnerabilities
258 known vulnerabilities affecting microsoft/edge_chromium.
Total CVEs
258
CISA KEV
9
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL13HIGH128MEDIUM110LOW7
Vulnerabilities
Page 4 of 13
CVE-2022-33649P3CRITICALCVSS 9.6fixed in 104.0.1293.472022-08-09
CVE-2022-33649 [CRITICAL] CVE-2022-33649: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2025-59251P3HIGHCVSS 7.6fixed in 140.0.3485.812025-09-24
CVE-2025-59251 [HIGH] CWE-121 CVE-2025-59251: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2026-57992P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-57992 [HIGH] CWE-416 CVE-2026-57992: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-21399P3HIGHCVSS 8.3fixed in 121.0.2277.982024-02-02
CVE-2024-21399 [HIGH] CWE-416 CVE-2024-21399: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2026-58596P3HIGHCVSS 8.3fixed in 150.0.4078.482026-07-12
CVE-2026-58596 [HIGH] CWE-822 CVE-2026-58596: Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2021-30614P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30614 [HIGH] CWE-787 CVE-2021-30614: Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
nvd
CVE-2026-57975P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-57975 [HIGH] CWE-843 CVE-2026-57975: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58293P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-58293 [HIGH] CWE-73 CVE-2026-58293: External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized atta
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57984P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-57984 [HIGH] CWE-416 CVE-2026-57984: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57986P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-57986 [HIGH] CWE-416 CVE-2026-57986: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58276P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-58276 [HIGH] CWE-416 CVE-2026-58276: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58294P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-58294 [HIGH] CWE-416 CVE-2026-58294: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58525P3HIGHCVSS 8.2fixed in 150.0.4078.502026-07-08
CVE-2026-58525 [HIGH] CWE-284 CVE-2026-58525: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2021-30610P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30610 [HIGH] CWE-416 CVE-2021-30610: Chromium: CVE-2021-30610 Use after free in Extensions API
Chromium: CVE-2021-30610 Use after free in Extensions API
nvd
CVE-2021-30620P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30620 [HIGH] CVE-2021-30620: Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
nvd
CVE-2025-29815P3HIGHCVSS 7.6fixed in 134.0.3124.662025-04-04
CVE-2025-29815 [HIGH] CWE-416 CVE-2025-29815: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-58292P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-58292 [HIGH] CWE-20 CVE-2026-58292: Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exec
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-31982P3HIGHCVSS 8.8fixed in 91.0.864.372023-07-01
CVE-2021-31982 [HIGH] CWE-693 CVE-2021-31982: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2023-23374P3HIGHCVSS 8.3fixed in 110.0.1587.412023-02-14
CVE-2023-23374 [HIGH] CVE-2023-23374: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2023-21775P3HIGHCVSS 8.3fixed in 108.0.1462.95fixed in 109.0.1518.702023-01-24
CVE-2023-21775 [HIGH] CVE-2023-21775: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd