Edge Chromium Microsoft Edge Chromium

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Edge Chromium.

By the Year

In 2026 there have been 79 vulnerabilities in Microsoft Edge Chromium with an average score of 7.0 out of ten. Last year, in 2025 Edge Chromium had 26 security vulnerabilities published. That is, 53 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.51.




Year Vulnerabilities Average Score
2026 79 6.96
2025 26 6.46
2024 50 6.05
2023 58 6.67
2022 34 7.14
2021 53 7.26
2020 3 5.37

It may take a day or so for new Edge Chromium vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Edge Chromium Security Vulnerabilities

Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-72970 8.3 - High - August 14, 2026

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-70339 5.4 - Medium - August 11, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Object Type Confusion

Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-66326 6.5 - Medium - August 03, 2026

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

AuthZ

Aug 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-66325 6.1 - Medium - August 03, 2026

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

SSRF

Aug 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-66322 7.1 - High - August 03, 2026

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Origin Validation Error

Aug 2026: Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-66311 6.2 - Medium - August 03, 2026

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

AuthZ

Aug 2026: Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-66317 5.4 - Medium - August 03, 2026

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

Origin Validation Error

Aug 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-65804 6.1 - Medium - August 03, 2026

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Code Injection

Aug 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-65802 7.4 - High - August 03, 2026

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

External Control of File Name or Path

Aug 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-66316 5.4 - Medium - August 03, 2026

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Origin Validation Error

Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-66315 7.5 - High - August 03, 2026

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Aug 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-66314 6.5 - Medium - August 03, 2026

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

TOCTTOU

Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-66312 6.5 - Medium - August 03, 2026

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Buffer Over-read

Aug 2026: Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-66313 6.8 - Medium - August 03, 2026

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Origin Validation Error

Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-66321 7.4 - High - August 03, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Object Type Confusion

Aug 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-66318 8.1 - High - August 03, 2026

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Origin Validation Error

Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57990 7.4 - High - July 26, 2026

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Files or Directories Accessible to External Parties

Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57989 7.4 - High - July 26, 2026

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Origin Validation Error

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57978 5.4 - Medium - July 26, 2026

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Origin Validation Error

Jul 2026: Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-57980 5.4 - Medium - July 17, 2026

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

Authentication Bypass Using an Alternate Path or Channel

Jul 2026: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-58596 8.3 - High - July 12, 2026

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Untrusted Pointer Dereference

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58281 8.3 - High - July 11, 2026

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Marshaling, Unmarshaling

Jul 2026: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-58525 8.2 - High - July 08, 2026

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Authorization

Jul 2026: Microsoft Edge for Android Security Feature Bypass Vulnerability
CVE-2026-58523 6.5 - Medium - July 03, 2026

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

Authorization

Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-58291 6.1 - Medium - July 03, 2026

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Operation on a Resource after Expiration or Release

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45489 6.5 - Medium - July 03, 2026

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Exposed Dangerous Method or Function

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58597 4.3 - Medium - July 03, 2026

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Insufficient UI Warning of Dangerous Operations

Jul 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58300 6.2 - Medium - July 03, 2026

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Absolute Path Traversal

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58524 5.4 - Medium - July 03, 2026

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

XSS

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58298 7.2 - High - July 03, 2026

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

XSS

Jul 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58297 7.1 - High - July 03, 2026

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Privacy violation

Jul 2026: Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-58296 7.1 - High - July 03, 2026

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Privacy violation

Jul 2026: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-58295 8.3 - High - July 03, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Object Type Confusion

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58294 7.5 - High - July 03, 2026

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58293 8.1 - High - July 03, 2026

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

External Control of File Name or Path

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58292 7.5 - High - July 03, 2026

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Improper Input Validation

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58290 7.5 - High - July 03, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Object Type Confusion

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58289 9 - Critical - July 03, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Object Type Confusion

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58288 8.3 - High - July 03, 2026

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58286 8.1 - High - July 03, 2026

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Authorization

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58284 8.3 - High - July 03, 2026

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

AuthZ

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58285 8.3 - High - July 03, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Object Type Confusion

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58278 5.4 - Medium - July 03, 2026

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

SSRF

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-58276 7.5 - High - July 03, 2026

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Jul 2026: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-57991 7.4 - High - July 03, 2026

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

insecure temporary file

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57986 7.5 - High - July 03, 2026

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57981 8.8 - High - July 03, 2026

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-57977 7.1 - High - July 03, 2026

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

XSS

Jul 2026: Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45488 5.4 - Medium - July 03, 2026

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

User Interface (UI) Misrepresentation of Critical Information

Jul 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-57974 8.8 - High - July 03, 2026

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Integer Overflow or Wraparound

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Edge Chromium or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe