Edge Chromium
by Microsoft
CVEs (324)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-30622 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30622 Use after free in WebApp Installs | ||
| CVE-2021-30620 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink | ||
| CVE-2021-30618 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30618 Inappropriate implementation in DevTools | ||
| CVE-2021-30616 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30616 Use after free in Media | ||
| CVE-2021-30614 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip | ||
| CVE-2021-30613 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30613 Use after free in Base internals | ||
| CVE-2021-30610 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30610 Use after free in Extensions API | ||
| CVE-2021-30609 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30609 Use after free in Sign-In | ||
| CVE-2021-30608 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30608 Use after free in Web Share | ||
| CVE-2021-30607 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30607 Use after free in Permissions | ||
| CVE-2021-30606 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30606 Use after free in Blink | ||
| CVE-2021-21157 | Hig | 0.58 | 8.8 | 0.09 | Feb 22, 2021 | Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21128 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21127 | Hig | 0.58 | 8.8 | 0.06 | Feb 9, 2021 | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension. | ||
| CVE-2021-21122 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21120 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21119 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2026-32208 | Hig | 0.57 | 8.8 | 0.01 | Jun 19, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-45495 | Hig | 0.57 | 8.8 | 0.01 | May 18, 2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2025-49713 | Hig | 0.57 | 8.8 | 0.01 | Jul 2, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30622 Use after free in WebApp Installs
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30616 Use after free in Media
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30613 Use after free in Base internals
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30610 Use after free in Extensions API
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30609 Use after free in Sign-In
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30608 Use after free in Web Share
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30607 Use after free in Permissions
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30606 Use after free in Blink
- risk 0.58cvss 8.8epss 0.09
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.07
Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.06
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.
- risk 0.58cvss 8.8epss 0.07
Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.07
Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.07
Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Page 2 of 17