{"schema_version":1,"title":"Microsoft Edge Chromium vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 31 vulnerabilities in Microsoft Edge Chromium: 0 in the last 7 days and 25 in the last 90 days, 3 of them critical and 3 exploited in the wild. The most recent, CVE-2026-88097, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/edge-chromium","json_url":"https://junglewise.ai/threats/technologies/edge-chromium.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/edge-chromium","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":10,"all_time":31,"critical":3,"exploited":3,"last_7_days":0,"last_30_days":13,"last_90_days":25,"last_365_days":29},"latest":[{"cve":"CVE-2026-88097","cvss":8.1,"epss":0.0026,"slug":"cve-2026-88097-use-after-free-in-microsoft-edge-chromium-based-allows-an","title":"Microsoft Edge use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-18T21:18:45.913+00:00","url":"https://junglewise.ai/threats/cve-2026-88097-use-after-free-in-microsoft-edge-chromium-based-allows-an"},{"cve":"CVE-2026-85893","cvss":8.8,"epss":0.0084,"slug":"cve-2026-85893-microsoft-edge-use-after-free-in-chromium","title":"Microsoft Edge use-after-free in Chromium","severity":"high","exploited":false,"published_at":"2026-09-15T23:19:12.11+00:00","url":"https://junglewise.ai/threats/cve-2026-85893-microsoft-edge-use-after-free-in-chromium"},{"cve":"CVE-2026-69486","cvss":8.8,"epss":0.0084,"slug":"cve-2026-69486-microsoft-edge-heap-based-buffer-overflow","title":"Microsoft Edge heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-15T23:17:41.633+00:00","url":"https://junglewise.ai/threats/cve-2026-69486-microsoft-edge-heap-based-buffer-overflow"},{"cve":"CVE-2026-85892","cvss":7.8,"epss":0.0021,"slug":"cve-2026-85892-microsoft-edge-race-condition-in-shared-resource-synchronization","title":"Microsoft Edge race condition in shared resource synchronization","severity":"high","exploited":false,"published_at":"2026-09-14T18:20:19.343+00:00","url":"https://junglewise.ai/threats/cve-2026-85892-microsoft-edge-race-condition-in-shared-resource-synchronization"},{"cve":"CVE-2026-77490","cvss":6.1,"epss":0.0042,"slug":"cve-2026-77490-microsoft-edge-cross-site-scripting-in-page-generation","title":"Microsoft Edge cross-site scripting in page generation","severity":"medium","exploited":false,"published_at":"2026-09-11T20:18:45.403+00:00","url":"https://junglewise.ai/threats/cve-2026-77490-microsoft-edge-cross-site-scripting-in-page-generation"},{"cve":"CVE-2026-72984","cvss":8.8,"epss":0.0082,"slug":"cve-2026-72984-microsoft-edge-type-confusion-in-resource-access","title":"Microsoft Edge type confusion in resource access","severity":"high","exploited":false,"published_at":"2026-08-28T20:19:44.943+00:00","url":"https://junglewise.ai/threats/cve-2026-72984-microsoft-edge-type-confusion-in-resource-access"},{"cve":"CVE-2026-70331","cvss":5.4,"epss":0.0041,"slug":"cve-2026-70331-microsoft-edge-for-ios-prompt-injection-vulnerability","title":"Microsoft Edge for iOS prompt injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:41.82+00:00","url":"https://junglewise.ai/threats/cve-2026-70331-microsoft-edge-for-ios-prompt-injection-vulnerability"},{"cve":"CVE-2026-70309","cvss":5.4,"epss":0.0021,"slug":"cve-2026-70309-microsoft-edge-origin-validation-error-security-feature-bypass","title":"Microsoft Edge origin validation error security feature bypass","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:40.267+00:00","url":"https://junglewise.ai/threats/cve-2026-70309-microsoft-edge-origin-validation-error-security-feature-bypass"},{"cve":"CVE-2026-66798","cvss":4.3,"epss":0.0079,"slug":"cve-2026-66798-microsoft-edge-use-after-free-in-chromium","title":"Microsoft Edge use-after-free in Chromium","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:34.673+00:00","url":"https://junglewise.ai/threats/cve-2026-66798-microsoft-edge-use-after-free-in-chromium"},{"cve":"CVE-2026-66324","cvss":6.5,"epss":0.0092,"slug":"cve-2026-66324-microsoft-edge-path-traversal-spoofing-vulnerability","title":"Microsoft Edge path traversal spoofing vulnerability","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:34.407+00:00","url":"https://junglewise.ai/threats/cve-2026-66324-microsoft-edge-path-traversal-spoofing-vulnerability"},{"cve":"CVE-2026-66323","cvss":5.4,"epss":0.0041,"slug":"cve-2026-66323-microsoft-edge-improper-neutralization-of-parameter-delimiters","title":"Microsoft Edge improper neutralization of parameter delimiters","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:34.28+00:00","url":"https://junglewise.ai/threats/cve-2026-66323-microsoft-edge-improper-neutralization-of-parameter-delimiters"},{"cve":"CVE-2026-62904","cvss":5.4,"epss":0.0039,"slug":"cve-2026-62904-microsoft-edge-incorrect-authorization-information-disclosure","title":"Microsoft Edge incorrect authorization information disclosure","severity":"medium","exploited":false,"published_at":"2026-08-28T20:19:25.13+00:00","url":"https://junglewise.ai/threats/cve-2026-62904-microsoft-edge-incorrect-authorization-information-disclosure"},{"cve":"CVE-2026-58616","cvss":4.4,"epss":0.003,"slug":"cve-2026-58616-microsoft-edge-copilot-chat-race-condition-information-disclosure","title":"Microsoft Edge Copilot Chat race condition information disclosure","severity":"medium","exploited":false,"published_at":"2026-08-28T20:18:44.927+00:00","url":"https://junglewise.ai/threats/cve-2026-58616-microsoft-edge-copilot-chat-race-condition-information-disclosure"},{"cve":"CVE-2026-72970","cvss":8.3,"epss":0.0073,"slug":"cve-2026-72970-microsoft-edge-heap-based-buffer-overflow","title":"Microsoft Edge heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-14T18:19:09.003+00:00","url":"https://junglewise.ai/threats/cve-2026-72970-microsoft-edge-heap-based-buffer-overflow"},{"cve":"CVE-2026-66326","cvss":6.5,"epss":0.0077,"slug":"cve-2026-66326-microsoft-edge-missing-authorization-allows-remote-code-execution","title":"Microsoft Edge missing authorization allows remote code execution","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.847+00:00","url":"https://junglewise.ai/threats/cve-2026-66326-microsoft-edge-missing-authorization-allows-remote-code-execution"},{"cve":"CVE-2026-66325","cvss":6.1,"epss":0.0039,"slug":"cve-2026-66325-microsoft-edge-server-side-request-forgery","title":"Microsoft Edge server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.703+00:00","url":"https://junglewise.ai/threats/cve-2026-66325-microsoft-edge-server-side-request-forgery"},{"cve":"CVE-2026-66322","cvss":7.1,"epss":0.0023,"slug":"cve-2026-66322-microsoft-edge-origin-validation-error-enabling-spoofing-attacks","title":"Microsoft Edge origin validation error enabling spoofing attacks","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.577+00:00","url":"https://junglewise.ai/threats/cve-2026-66322-microsoft-edge-origin-validation-error-enabling-spoofing-attacks"},{"cve":"CVE-2026-66321","cvss":7.4,"epss":0.0107,"slug":"cve-2026-66321-microsoft-edge-type-confusion-vulnerability","title":"Microsoft Edge type confusion vulnerability","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.44+00:00","url":"https://junglewise.ai/threats/cve-2026-66321-microsoft-edge-type-confusion-vulnerability"},{"cve":"CVE-2026-66318","cvss":8.1,"epss":0.0036,"slug":"cve-2026-66318-microsoft-edge-origin-validation-error-allows-information","title":"Microsoft Edge origin validation error allows information disclosure","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.317+00:00","url":"https://junglewise.ai/threats/cve-2026-66318-microsoft-edge-origin-validation-error-allows-information"},{"cve":"CVE-2026-66317","cvss":5.4,"epss":0.0021,"slug":"cve-2026-66317-microsoft-edge-origin-validation-error-allows-network-tampering","title":"Microsoft Edge origin validation error allows network tampering","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.183+00:00","url":"https://junglewise.ai/threats/cve-2026-66317-microsoft-edge-origin-validation-error-allows-network-tampering"},{"cve":"CVE-2026-66316","cvss":5.4,"epss":0.0021,"slug":"cve-2026-66316-microsoft-edge-origin-validation-bypass-allowing-spoofing","title":"Microsoft Edge origin validation bypass allowing spoofing","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:39.06+00:00","url":"https://junglewise.ai/threats/cve-2026-66316-microsoft-edge-origin-validation-bypass-allowing-spoofing"},{"cve":"CVE-2026-66315","cvss":7.5,"epss":0.0061,"slug":"cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium","title":"Microsoft Edge use-after-free vulnerability in Chromium","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:38.927+00:00","url":"https://junglewise.ai/threats/cve-2026-66315-microsoft-edge-use-after-free-vulnerability-in-chromium"},{"cve":"CVE-2026-66314","cvss":6.5,"epss":0.0057,"slug":"cve-2026-66314-microsoft-edge-time-of-check-time-of-use-race-condition","title":"Microsoft Edge time-of-check time-of-use race condition","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:38.797+00:00","url":"https://junglewise.ai/threats/cve-2026-66314-microsoft-edge-time-of-check-time-of-use-race-condition"},{"cve":"CVE-2026-66313","cvss":6.8,"epss":0.0023,"slug":"cve-2026-66313-microsoft-edge-origin-validation-error-allows-local-tampering","title":"Microsoft Edge origin validation error allows local tampering","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:38.647+00:00","url":"https://junglewise.ai/threats/cve-2026-66313-microsoft-edge-origin-validation-error-allows-local-tampering"},{"cve":"CVE-2026-66312","cvss":6.5,"epss":0.011,"slug":"cve-2026-66312-microsoft-edge-buffer-over-read-remote-code-execution","title":"Microsoft Edge buffer over-read remote code execution","severity":"medium","exploited":false,"published_at":"2026-08-04T00:17:38.51+00:00","url":"https://junglewise.ai/threats/cve-2026-66312-microsoft-edge-buffer-over-read-remote-code-execution"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":11},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":963,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":167,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"}],"technology":{"hub":true,"name":"Microsoft Edge Chromium","slug":"edge-chromium","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":[],"homepage":"https://www.microsoft.com/edge","description":"Microsoft Edge Chromium is a web browser based on the open-source Chromium project.","url":"https://junglewise.ai/threats/technologies/edge-chromium"},"most_severe":[{"cve":"CVE-2025-5419","cvss":8.8,"epss":0.035,"slug":"cve-2025-5419-google-chromium-v8-out-of-bounds-read-and-write","title":"Google Chromium V8 out-of-bounds read and write","severity":"critical","exploited":true,"published_at":"2025-06-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-5419-google-chromium-v8-out-of-bounds-read-and-write"},{"cve":"CVE-2025-14174","cvss":8.8,"epss":0.0031,"slug":"cve-2025-14174-google-chromium-out-of-bounds-memory-access-in-angle","title":"Google Chromium out of bounds memory access in ANGLE","severity":"critical","exploited":true,"published_at":"2025-12-12T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-14174-google-chromium-out-of-bounds-memory-access-in-angle"},{"cve":"CVE-2024-7965","cvss":8.8,"slug":"cve-2024-7965-google-chromium-v8-inappropriate-implementation-vulnerability","title":"Google Chromium V8 Inappropriate Implementation Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7965-google-chromium-v8-inappropriate-implementation-vulnerability"},{"cve":"CVE-2026-85893","cvss":8.8,"epss":0.0084,"slug":"cve-2026-85893-microsoft-edge-use-after-free-in-chromium","title":"Microsoft Edge use-after-free in Chromium","severity":"high","exploited":false,"published_at":"2026-09-15T23:19:12.11+00:00","url":"https://junglewise.ai/threats/cve-2026-85893-microsoft-edge-use-after-free-in-chromium"},{"cve":"CVE-2026-69486","cvss":8.8,"epss":0.0084,"slug":"cve-2026-69486-microsoft-edge-heap-based-buffer-overflow","title":"Microsoft Edge heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-09-15T23:17:41.633+00:00","url":"https://junglewise.ai/threats/cve-2026-69486-microsoft-edge-heap-based-buffer-overflow"},{"cve":"CVE-2026-72984","cvss":8.8,"epss":0.0082,"slug":"cve-2026-72984-microsoft-edge-type-confusion-in-resource-access","title":"Microsoft Edge type confusion in resource access","severity":"high","exploited":false,"published_at":"2026-08-28T20:19:44.943+00:00","url":"https://junglewise.ai/threats/cve-2026-72984-microsoft-edge-type-confusion-in-resource-access"},{"cve":"CVE-2026-72970","cvss":8.3,"epss":0.0073,"slug":"cve-2026-72970-microsoft-edge-heap-based-buffer-overflow","title":"Microsoft Edge heap-based buffer overflow","severity":"high","exploited":false,"published_at":"2026-08-14T18:19:09.003+00:00","url":"https://junglewise.ai/threats/cve-2026-72970-microsoft-edge-heap-based-buffer-overflow"},{"cve":"CVE-2026-66318","cvss":8.1,"epss":0.0036,"slug":"cve-2026-66318-microsoft-edge-origin-validation-error-allows-information","title":"Microsoft Edge origin validation error allows information disclosure","severity":"high","exploited":false,"published_at":"2026-08-04T00:17:39.317+00:00","url":"https://junglewise.ai/threats/cve-2026-66318-microsoft-edge-origin-validation-error-allows-information"},{"cve":"CVE-2026-88097","cvss":8.1,"epss":0.0026,"slug":"cve-2026-88097-use-after-free-in-microsoft-edge-chromium-based-allows-an","title":"Microsoft Edge use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-09-18T21:18:45.913+00:00","url":"https://junglewise.ai/threats/cve-2026-88097-use-after-free-in-microsoft-edge-chromium-based-allows-an"},{"cve":"CVE-2026-85892","cvss":7.8,"epss":0.0021,"slug":"cve-2026-85892-microsoft-edge-race-condition-in-shared-resource-synchronization","title":"Microsoft Edge race condition in shared resource synchronization","severity":"high","exploited":false,"published_at":"2026-09-14T18:20:19.343+00:00","url":"https://junglewise.ai/threats/cve-2026-85892-microsoft-edge-race-condition-in-shared-resource-synchronization"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}