Microsoft Edge Chromium vulnerabilities
258 known vulnerabilities affecting microsoft/edge_chromium.
Total CVEs
258
CISA KEV
9
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL13HIGH128MEDIUM110LOW7
Vulnerabilities
Page 6 of 13
CVE-2021-30609P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30609 [HIGH] CWE-416 CVE-2021-30609: Chromium: CVE-2021-30609 Use after free in Sign-In
Chromium: CVE-2021-30609 Use after free in Sign-In
nvd
CVE-2021-30613P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30613 [HIGH] CWE-416 CVE-2021-30613: Chromium: CVE-2021-30613 Use after free in Base internals
Chromium: CVE-2021-30613 Use after free in Base internals
nvd
CVE-2021-30624P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30624 [HIGH] CWE-416 CVE-2021-30624: Chromium: CVE-2021-30624 Use after free in Autofill
Chromium: CVE-2021-30624 Use after free in Autofill
nvd
CVE-2021-30622P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30622 [HIGH] CWE-416 CVE-2021-30622: Chromium: CVE-2021-30622 Use after free in WebApp Installs
Chromium: CVE-2021-30622 Use after free in WebApp Installs
nvd
CVE-2021-30623P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30623 [HIGH] CWE-416 CVE-2021-30623: Chromium: CVE-2021-30623 Use after free in Bookmarks
Chromium: CVE-2021-30623 Use after free in Bookmarks
nvd
CVE-2026-57991P3HIGHCVSS 7.4fixed in 150.0.4078.482026-07-03
CVE-2026-57991 [HIGH] CWE-59 CVE-2026-57991: Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) al
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58290P3HIGHCVSS 7.5fixed in 150.0.4078.482026-07-03
CVE-2026-58290 [HIGH] CWE-843 CVE-2026-58290: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-21135P3MEDIUMCVSS 6.5fixed in 88.0.705.502021-02-09
CVE-2021-21135 [MEDIUM] CWE-346 CVE-2021-21135: Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a rem
Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-30607P3HIGHCVSS 8.8≤ 93.0.4577.632021-09-03
CVE-2021-30607 [HIGH] CWE-416 CVE-2021-30607: Chromium: CVE-2021-30607 Use after free in Permissions
Chromium: CVE-2021-30607 Use after free in Permissions
nvd
CVE-2025-29834P3HIGHCVSS 7.5fixed in 134.0.3124.932025-04-12
CVE-2025-29834 [HIGH] CWE-125 CVE-2025-29834: Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute cod
Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-21385P3HIGHCVSS 8.3fixed in 121.0.2277.832024-01-26
CVE-2024-21385 [HIGH] CWE-416 CVE-2024-21385: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-29350P3HIGHCVSS 7.5fixed in 113.0.1774.352023-05-05
CVE-2023-29350 [HIGH] CWE-269 CVE-2023-29350: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2024-43472P3HIGHCVSS 8.3fixed in 127.0.2651.1052024-08-16
CVE-2024-43472 [HIGH] CWE-416 CVE-2024-43472: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-36741P3HIGHCVSS 7.5fixed in 116.0.1938.622023-08-26
CVE-2023-36741 [HIGH] CWE-416 CVE-2023-36741: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2026-41107P3HIGHCVSS 7.4fixed in 148.0.3967.552026-05-12
CVE-2026-41107 [HIGH] CWE-73 CVE-2026-41107: External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized atta
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-57993P3HIGHCVSS 7.4fixed in 150.0.4078.482026-07-03
CVE-2026-57993 [HIGH] CWE-918 CVE-2026-57993: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacke
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-29146P3HIGHCVSS 8.3fixed in 101.0.1210.322023-06-29
CVE-2022-29146 [HIGH] CVE-2022-29146: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-21796P3HIGHCVSS 8.3fixed in 108.0.1462.952023-01-24
CVE-2023-21796 [HIGH] CVE-2023-21796: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-21795P3HIGHCVSS 8.3fixed in 109.0.1518.702023-01-24
CVE-2023-21795 [HIGH] CWE-416 CVE-2023-21795: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2021-33741P3HIGHCVSS 7.5fixed in 91.0.864.412021-06-08
CVE-2021-33741 [HIGH] CVE-2021-33741: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd