Edge Chromium
by Microsoft
CVEs (324)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-30615 | Med | 0.43 | 6.5 | 0.06 | Sep 3, 2021 | Chromium: CVE-2021-30615 Cross-origin data leak in Navigation | ||
| CVE-2021-21139 | Med | 0.43 | 6.5 | 0.05 | Feb 9, 2021 | Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | ||
| CVE-2021-21137 | Med | 0.43 | 6.5 | 0.06 | Feb 9, 2021 | Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page. | ||
| CVE-2021-21136 | Med | 0.43 | 6.5 | 0.04 | Feb 9, 2021 | Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2021-21134 | Med | 0.43 | 6.5 | 0.05 | Feb 9, 2021 | Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page. | ||
| CVE-2021-21131 | Med | 0.43 | 6.5 | 0.08 | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | ||
| CVE-2021-21130 | Med | 0.43 | 6.5 | 0.05 | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | ||
| CVE-2021-21129 | Med | 0.43 | 6.5 | 0.05 | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | ||
| CVE-2021-21126 | Med | 0.43 | 6.5 | 0.09 | Feb 9, 2021 | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. | ||
| CVE-2021-21123 | Med | 0.43 | 6.5 | 0.10 | Feb 9, 2021 | Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | ||
| CVE-2019-1023 | Med | 0.43 | 6.5 | 0.05 | Jun 12, 2019 | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. In a web-based… | ||
| CVE-2019-0990 | Med | 0.43 | 6.5 | 0.05 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2026-66326 | Med | 0.42 | 6.5 | 0.01 | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-66314 | Med | 0.42 | 6.5 | 0.01 | Aug 4, 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-66312 | Med | 0.42 | 6.5 | 0.01 | Aug 4, 2026 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-42891 | Med | 0.42 | 6.5 | 0.00 | May 12, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-0391 | Med | 0.42 | 6.5 | 0.01 | Feb 5, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-29825 | Med | 0.42 | 6.5 | 0.01 | May 2, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-29806 | Med | 0.42 | 6.5 | 0.01 | Mar 23, 2025 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21283 | Med | 0.42 | 6.5 | 0.01 | Feb 6, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
- risk 0.43cvss 6.5epss 0.06
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
- risk 0.43cvss 6.5epss 0.05
Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.06
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.04
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.05
Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.08
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.05
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.05
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.09
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.
- risk 0.43cvss 6.5epss 0.10
Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. In a web-based…
- risk 0.43cvss 6.5epss 0.05
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.42cvss 6.5epss 0.01
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.01
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.00
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Page 7 of 17