Msrc Microsoft Edge vulnerabilities
1,721 known vulnerabilities affecting msrc/microsoft_edge.
Total CVEs
1,721
CISA KEV
58
actively exploited
Public exploits
16
Exploited in wild
48
Severity breakdown
CRITICAL66HIGH965MEDIUM659LOW24UNKNOWN7
Vulnerabilities
Page 22 of 87
CVE-2024-7532HIGHCVSS 8.82024-08-13
CVE-2024-7532 [HIGH] Chromium: CVE-2024-7533 Use after free in Sharing
Chromium: CVE-2024-7533 Use after free in Sharing
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
127.0.2651.98
127.0.6533.99/.100
8/8/
msrc
CVE-2024-7964HIGHCVSS 8.82024-08-13
CVE-2024-7964 [HIGH] Chromium: CVE-2024-7964 Use after free in Passwords
Chromium: CVE-2024-7964 Use after free in Passwords
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (
msrc
CVE-2024-7965HIGHCVSS 8.8KEV2024-08-13
CVE-2024-7965 [HIGH] Chromium: CVE-2024-7965 Inappropriate implementation in V8
Chromium: CVE-2024-7965 Inappropriate implementation in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Mi
msrc
CVE-2024-38218HIGHCVSS 8.42024-08-13
CVE-2024-38218 [HIGH] CWE-843 Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
127.0.2651.98
127.0.6533.99/.100
8/8/2024
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remo
msrc
CVE-2024-7967HIGHCVSS 8.82024-08-13
CVE-2024-7967 [HIGH] Chromium: CVE-2024-7967 Heap buffer overflow in Fonts
Chromium: CVE-2024-7967 Heap buffer overflow in Fonts
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Ed
msrc
CVE-2024-7973HIGHCVSS 8.82024-08-13
CVE-2024-7973 [HIGH] Chromium: CVE-2024-7973 Heap buffer overflow in PDFium
Chromium: CVE-2024-7973 Heap buffer overflow in PDFium
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft
msrc
CVE-2024-38219MEDIUMCVSS 6.52024-08-13
CVE-2024-38219 [MEDIUM] CWE-843 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to minor loss of confidentiality (C:L), integrity (I:L) and availability (A:L). What does that mean for this vulnerability?
While we cannot rule out the impact to Confidentiality, Integrity, and Availability, the ability to exploit this v
msrc
CVE-2024-41879MEDIUMCVSS 7.82024-08-13
CVE-2024-41879 [HIGH] CWE-125 Adobe Systems Incorporated: CVE-2024-41879 Adobe PDF Viewer Remote Code Execution Vulnerability
Adobe Systems Incorporated: CVE-2024-41879 Adobe PDF Viewer Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Channel
Microsoft Edge Version
Based on Chromium Version
Date Released
Stable
128.0.2739.42
128.0.6613.84/.85
8/22/2024
FAQ: Why is this Adobe CVE included in the Security Update Guide?
The vulnerabili
msrc
CVE-2024-7976MEDIUMCVSS 4.32024-08-13
CVE-2024-7976 [MEDIUM] Chromium: CVE-2024-7976 Inappropriate implementation in FedCM
Chromium: CVE-2024-7976 Inappropriate implementation in FedCM
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consum
msrc
CVE-2024-43472MEDIUMCVSS 5.82024-08-13
CVE-2024-43472 [MEDIUM] CWE-416 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
FAQ: What privileges could be gained by an attacker who successfully exploited
msrc
CVE-2024-7981MEDIUMCVSS 4.32024-08-13
CVE-2024-7981 [MEDIUM] Chromium: CVE-2024-7981 Inappropriate implementation in Views
Chromium: CVE-2024-7981 Inappropriate implementation in Views
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consum
msrc
CVE-2024-7978MEDIUMCVSS 4.32024-08-13
CVE-2024-7978 [MEDIUM] Chromium: CVE-2024-7978 Insufficient policy enforcement in Data Transfer
Chromium: CVE-2024-7978 Insufficient policy enforcement in Data Transfer
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software
msrc
CVE-2024-8035MEDIUMCVSS 4.32024-08-13
CVE-2024-8035 [MEDIUM] Chromium: CVE-2024-8035 Inappropriate implementation in Extensions
Chromium: CVE-2024-8035 Inappropriate implementation in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which
msrc
CVE-2024-8034MEDIUMCVSS 4.32024-08-13
CVE-2024-8034 [MEDIUM] Chromium: CVE-2024-8034 Inappropriate implementation in Custom Tabs
Chromium: CVE-2024-8034 Inappropriate implementation in Custom Tabs
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) whi
msrc
CVE-2024-7975MEDIUMCVSS 4.32024-08-13
CVE-2024-7975 [MEDIUM] Chromium: CVE-2024-7975 Inappropriate implementation in Permissions
Chromium: CVE-2024-7975 Inappropriate implementation in Permissions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) whi
msrc
CVE-2024-8033MEDIUMCVSS 4.32024-08-13
CVE-2024-8033 [MEDIUM] Chromium: CVE-2024-8033 Inappropriate implementation in WebApp Installs
Chromium: CVE-2024-8033 Inappropriate implementation in WebApp Installs
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (
msrc
CVE-2024-38207MEDIUMCVSS 6.32024-08-13
CVE-2024-38207 [MEDIUM] CWE-843 Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to minor loss of confidentiality (C:L), integrity (I:L) and availability (A:L). What does that mean for this vulnerability?
While we cannot rule out the impact to Confidentiality, Integrity, and Availability, the ability to exploit this vulnerability by
msrc
CVE-2024-6779CRITICALCVSS 9.62024-07-09
CVE-2024-6779 [CRITICAL] Chromium: CVE-2024-6779 Out of bounds memory access in V8
Chromium: CVE-2024-6779 Out of bounds memory access in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by
msrc
CVE-2024-6778HIGHCVSS 7.52024-07-09
CVE-2024-6778 [HIGH] Chromium: CVE-2024-6778 Race in DevTools
Chromium: CVE-2024-6778 Race in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is
msrc
CVE-2024-6988HIGHCVSS 8.82024-07-09
CVE-2024-6988 [HIGH] Chromium: CVE-2024-6988 Use after free in Downloads
Chromium: CVE-2024-6988 Use after free in Downloads
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (
msrc