Microsoft Edge Chromium
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Edge Chromium.
By the Year
In 2026 there have been 60 vulnerabilities in Microsoft Edge Chromium with an average score of 7.1 out of ten. Last year, in 2025 Edge Chromium had 26 security vulnerabilities published. That is, 34 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.60.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 60 | 7.06 |
| 2025 | 26 | 6.46 |
| 2024 | 49 | 6.14 |
| 2023 | 58 | 6.65 |
| 2022 | 34 | 7.14 |
| 2021 | 49 | 7.41 |
| 2020 | 2 | 6.50 |
It may take a day or so for new Edge Chromium vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Edge Chromium Security Vulnerabilities
Jul 2026: Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-57980
5.4 - Medium
- July 17, 2026
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
Authentication Bypass Using an Alternate Path or Channel
Jul 2026: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-58596
8.3 - High
- July 12, 2026
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Untrusted Pointer Dereference
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58281
8.3 - High
- July 11, 2026
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Marshaling, Unmarshaling
Jul 2026: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-58525
8.2 - High
- July 08, 2026
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Authorization
Jul 2026: Microsoft Edge for Android Security Feature Bypass Vulnerability
CVE-2026-58523
6.5 - Medium
- July 03, 2026
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
Authorization
Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-58291
6.1 - Medium
- July 03, 2026
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Operation on a Resource after Expiration or Release
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45489
6.5 - Medium
- July 03, 2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Exposed Dangerous Method or Function
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58597
4.3 - Medium
- July 03, 2026
Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Insufficient UI Warning of Dangerous Operations
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58524
5.4 - Medium
- July 03, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
XSS
Jul 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58300
6.2 - Medium
- July 03, 2026
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Absolute Path Traversal
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58298
7.2 - High
- July 03, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
XSS
Jul 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58297
7.1 - High
- July 03, 2026
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
Privacy violation
Jul 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58296
7.1 - High
- July 03, 2026
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
Privacy violation
Jul 2026: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-58295
8.3 - High
- July 03, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Object Type Confusion
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58294
7.5 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58293
8.1 - High
- July 03, 2026
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
External Control of File Name or Path
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58292
7.5 - High
- July 03, 2026
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper Input Validation
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58290
7.5 - High
- July 03, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Object Type Confusion
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58289
9 - Critical
- July 03, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Object Type Confusion
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58288
8.3 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58286
8.1 - High
- July 03, 2026
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Authorization
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58285
8.3 - High
- July 03, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Object Type Confusion
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58284
8.3 - High
- July 03, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
AuthZ
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58278
5.4 - Medium
- July 03, 2026
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
SSRF
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58276
7.5 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57991
7.4 - High
- July 03, 2026
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
insecure temporary file
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57986
7.5 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57977
7.1 - High
- July 03, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
XSS
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57981
8.8 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45488
5.4 - Medium
- July 03, 2026
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
User Interface (UI) Misrepresentation of Critical Information
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57974
8.8 - High
- July 03, 2026
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Integer Overflow or Wraparound
Jul 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58522
6.8 - Medium
- July 03, 2026
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Relative Path Traversal
Jul 2026: Microsoft Edge for Android Remote Code Execution Vulnerability
CVE-2026-58299
7.5 - High
- July 03, 2026
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
TOCTTOU
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58287
8.3 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58283
8.1 - High
- July 03, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Object Type Confusion
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58282
8.1 - High
- July 03, 2026
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Authorization
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-56646
6.5 - Medium
- July 03, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Information Disclosure
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57993
7.4 - High
- July 03, 2026
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
SSRF
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57988
7.1 - High
- July 03, 2026
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Relative Path Traversal
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57992
7.5 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57987
6.5 - Medium
- July 03, 2026
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
SSRF
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57984
7.5 - High
- July 03, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57985
7.6 - High
- July 03, 2026
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper Input Validation
Jul 2026: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-57983
8.7 - High
- July 03, 2026
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
AuthZ
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57975
7.5 - High
- July 03, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Object Type Confusion
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-56645
8.8 - High
- July 03, 2026
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-55945
4.2 - Medium
- July 03, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
Race Condition
Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-50521
8.3 - High
- July 01, 2026
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Dangling pointer
Jun 2026: Microsoft Entra ID Spoofing Vulnerability
CVE-2026-32208
8.8 - High
- June 19, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
XSS
May 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45494
5.4 - Medium
- May 18, 2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Edge Chromium or by Microsoft? Click the Watch button to subscribe.