Microsoft
Microsoft Edge Chromium: vulnerabilidades y CVE
Microsoft Edge Chromium tiene 308 vulnerabilidades publicadas, 97 de ellas en los últimos 12 meses. 14 son críticas y 9 figuran en el catálogo de explotación activa de CISA.
CVE308
Últimos 12 meses97
Críticas14
Explotadas activamente9
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-14174 | Alta (8.8) | 22% | ⚠ Explotación activa | 12 dic 2025 | Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
| CVE-2025-5419 | Alta (8.8) | 7.8% | ⚠ Explotación activa | 3 jun 2025 | Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-7965 | Alta (8.8) | 19% | ⚠ Explotación activa | 21 ago 2024 | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2023-4762 | Alta (8.8) | 41% | ⚠ Explotación activa | 5 sept 2023 | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) |
| CVE-2023-6345 | Crítica (9.6) | 16% | ⚠ Explotación activa | 29 nov 2023 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security… |
| CVE-2023-5217 | Alta (8.8) | 49% | ⚠ Explotación activa | 28 sept 2023 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security… |
| CVE-2023-4863 | Alta (8.8) | 100% | ⚠ Explotación activa | 12 sept 2023 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:… |
| CVE-2022-4135 | Crítica (9.6) | 32% | ⚠ Explotación activa | 25 nov 2022 | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security… |
| CVE-2020-16009 | Alta (8.8) | 48% | ⚠ Explotación activa | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88097 | Alta (7.8) | 0.26% | — | 18 sept 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-85893 | Alta (8.8) | 0.82% | — | 15 sept 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69486 | Alta (8.8) | 0.82% | — | 15 sept 2026 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-85892 | Alta (7.8) | 0.20% | — | 14 sept 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-77490 | Media (6.1) | 0.41% | — | 11 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-72984 | Alta (8.8) | 0.82% | — | 28 ago 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-70331 | Media (5.4) | 0.41% | — | 28 ago 2026 | Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-70309 | Media (5.4) | 0.21% | — | 28 ago 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-66798 | Media (4.3) | 0.79% | — | 28 ago 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66324 | Media (6.5) | 0.92% | — | 28 ago 2026 | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66323 | Media (5.4) | 0.41% | — | 28 ago 2026 | Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-62904 | Media (5.4) | 0.39% | — | 28 ago 2026 | Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-58616 | Baja (3) | 0.29% | — | 28 ago 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. |
| CVE-2026-72970 | Alta (8.3) | 0.73% | — | 14 ago 2026 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-70339 | Media (5.4) | 0.41% | — | 11 ago 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66326 | Alta (8.8) | 0.77% | — | 4 ago 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66325 | Media (6.1) | 0.39% | — | 4 ago 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66322 | Media (5.4) | 0.23% | — | 4 ago 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66321 | Crítica (9.6) | 1.1% | — | 4 ago 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66318 | Alta (8.1) | 0.36% | — | 4 ago 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-66317 | Media (5.4) | 0.21% | — | 4 ago 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-66316 | Media (5.4) | 0.21% | — | 4 ago 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66315 | Alta (7.5) | 0.61% | — | 4 ago 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66314 | Media (5.3) | 0.57% | — | 4 ago 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-66313 | Media (6.8) | 0.23% | — | 4 ago 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-66312 | Alta (8.8) | 1.1% | — | 4 ago 2026 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2026-66311 | Media (6.2) | 0.40% | — | 4 ago 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-65804 | Media (6.1) | 0.41% | — | 4 ago 2026 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-65802 | Alta (7.4) | 0.92% | — | 4 ago 2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-57990 | Alta (7.4) | 0.92% | — | 26 jul 2026 | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.