Microsoft Edge Chromium vulnerabilities
258 known vulnerabilities affecting microsoft/edge_chromium.
Total CVEs
258
CISA KEV
9
actively exploited
Public exploits
9
Exploited in wild
9
Severity breakdown
CRITICAL13HIGH128MEDIUM110LOW7
Vulnerabilities
Page 8 of 13
CVE-2026-57987P3MEDIUMCVSS 6.5fixed in 150.0.4078.482026-07-03
CVE-2026-57987 [MEDIUM] CWE-918 CVE-2026-57987: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacke
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-23263P3HIGHCVSS 7.7fixed in 98.0.1108.432022-02-07
CVE-2022-23263 [HIGH] CVE-2022-23263: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2021-42308P3HIGHCVSS 7.5fixed in 96.0.1054.292021-11-24
CVE-2021-42308 [HIGH] CWE-290 CVE-2021-42308: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2026-58297P3HIGHCVSS 7.1fixed in 150.0.4078.482026-07-03
CVE-2026-58297 [HIGH] CWE-359 CVE-2026-58297: Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58296P3HIGHCVSS 7.1fixed in 150.0.4078.482026-07-03
CVE-2026-58296 [HIGH] CWE-359 CVE-2026-58296: Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58283P3MEDIUMCVSS 6.9fixed in 150.0.4078.482026-07-03
CVE-2026-58283 [MEDIUM] CWE-843 CVE-2026-58283: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-58286P3MEDIUMCVSS 6.9fixed in 150.0.4078.482026-07-03
CVE-2026-58286 [MEDIUM] CWE-284 CVE-2026-58286: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-58282P3MEDIUMCVSS 6.9fixed in 150.0.4078.482026-07-03
CVE-2026-58282 [MEDIUM] CWE-284 CVE-2026-58282: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-60711P3MEDIUMCVSS 6.3fixed in 142.0.3595.532025-10-31
CVE-2025-60711 [MEDIUM] CWE-693 CVE-2025-60711: Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to e
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-21130P3MEDIUMCVSS 6.5fixed in 88.0.705.502021-02-09
CVE-2021-21130 [MEDIUM] CVE-2021-21130: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2021-21129P3MEDIUMCVSS 6.5fixed in 88.0.705.502021-02-09
CVE-2021-21129 [MEDIUM] CVE-2021-21129: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2026-21223P3HIGHCVSS 7.1fixed in 144.0.3719.822026-01-16
CVE-2026-21223 [HIGH] CWE-269 CVE-2026-21223: Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to by
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2023-38187P3MEDIUMCVSS 6.5fixed in 115.0.1901.1832023-07-21
CVE-2023-38187 [MEDIUM] CWE-269 CVE-2023-38187: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2026-58523P3MEDIUMCVSS 6.5fixed in 150.0.4078.482026-07-03
CVE-2026-58523 [MEDIUM] CWE-284 CVE-2026-58523: Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a se
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2021-21134P3MEDIUMCVSS 6.5fixed in 88.0.705.502021-02-09
CVE-2021-21134 [MEDIUM] CWE-290 CVE-2021-21134: Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote at
Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2022-41115P3MEDIUMCVSS 6.6fixed in 108.0.1462.412022-12-13
CVE-2022-41115 [MEDIUM] CVE-2022-41115: Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
nvd
CVE-2025-29806P3MEDIUMCVSS 6.5fixed in 129.0.2792.522025-03-23
CVE-2025-29806 [MEDIUM] CWE-843 CVE-2025-29806: No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-21139P4MEDIUMCVSS 6.5fixed in 88.0.705.502021-02-09
CVE-2021-21139 [MEDIUM] CWE-1021 CVE-2021-21139: Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remo
Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-21133P3MEDIUMCVSS 6.5fixed in 88.0.705.502021-02-09
CVE-2021-21133 [MEDIUM] CVE-2021-21133: Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attac
Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2023-38157P4MEDIUMCVSS 6.5fixed in 115.0.1901.2002023-08-07
CVE-2023-38157 [MEDIUM] CWE-693 CVE-2023-38157: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd