VYPR
Vypr IntelligenceAI-generatedAug 4, 2026· 14 CVEs

Microsoft Edge Chromium: 14 Vulnerabilities Disclosed in Single Batch on August 4, 2026

Microsoft Edge Chromium faced a coordinated disclosure of 14 vulnerabilities on August 4, 2026, including high-severity flaws enabling code execution and information disclosure.

Key findings

  • Microsoft Edge Chromium: 14 CVEs disclosed on August 4, 2026, covering diverse vulnerabilities.
  • High severity flaws include origin validation errors, type confusion, use-after-free, and external control of file path.
  • Vulnerabilities could lead to remote code execution, information disclosure, spoofing, and tampering.
  • Affected areas include authorization, origin validation, and memory safety across the browser.
  • Microsoft has released patches; users should update Edge Chromium promptly.

On August 4, 2026, Microsoft released a batch of 14 security advisories addressing vulnerabilities in its Edge Chromium browser. The disclosures, all published on the same day, highlight a range of issues including authorization flaws, origin validation errors, and memory safety bugs, with several carrying high severity ratings. These vulnerabilities could allow attackers to execute code, disclose information, or perform spoofing and tampering attacks over a network.

Several CVEs point to issues with how Edge handles origins and authorization. CVE-2026-66322 and CVE-2026-66318, both rated High, stem from origin validation errors, with the former allowing spoofing and the latter information disclosure. Similarly, CVE-2026-66317, CVE-2026-66316, and CVE-2026-66313 also involve origin validation errors, leading to tampering and spoofing. Missing authorization is another theme, with CVE-2026-66326 (Medium) and CVE-2026-66312 (Medium) allowing unauthorized attackers to execute code or tamper with the system, respectively.

Memory safety vulnerabilities are also present in this batch. CVE-2026-66315, a High severity "use after free" bug, could enable attackers to execute code. CVE-2026-66321, another High severity flaw, involves "type confusion" and could lead to remote code execution. A buffer over-read vulnerability, CVE-2026-66311 (Medium), also presents a risk of code execution.

Other notable vulnerabilities include a Server-Side Request Forgery (SSRF) in CVE-2026-66325 (Medium), which could be exploited for spoofing. CVE-2026-66314, a TOCTOU race condition, allows for information disclosure. Additionally, CVE-2026-65804 (High) involves improper control of code generation, leading to code injection and spoofing, specifically affecting Edge for Android. CVE-2026-65804 is noted as an "External control of file name or path" vulnerability.

Microsoft has addressed these vulnerabilities through updates to the Edge Chromium browser. Users are advised to ensure their browsers are updated to the latest version to mitigate these risks. The consistent disclosure of these vulnerabilities on a single date suggests a coordinated patching and release cycle by Microsoft.

This batch of vulnerabilities underscores the ongoing security challenges in complex software like web browsers. Users of Microsoft Edge Chromium should remain vigilant and apply updates promptly to protect against potential exploitation. The variety of vulnerability types indicates a broad attack surface that requires continuous security attention from both the vendor and users. The disclosures cover a range of impacts, from information disclosure to remote code execution, emphasizing the importance of timely patching.

AI-written article. Grounded in 14 CVE records listed below.