📦 Edge

by Microsoft

🔍 What is Edge?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-7971

CRITICAL CVSS 9.6 Aug 21, 2024

This is a type confusion vulnerability in Chrome's V8 JavaScript engine that allows remote attackers to trigger heap corruption via malicious HTML pages. Successful exploitation could lead to arbitrar...

CVE-2024-41879

HIGH CVSS 7.8 Aug 26, 2024

CVE-2024-41879 is an out-of-bounds write vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution when a user opens a malicious PDF file. This affects users running vulnerable v...

CVE-2021-30624

HIGH CVSS 8.8 Sep 3, 2021

CVE-2021-30624 is a use-after-free vulnerability in Chromium's Autofill feature that allows attackers to execute arbitrary code or cause a denial of service. This affects all Chromium-based browsers i...

CVE-2021-30606

HIGH CVSS 8.8 Sep 3, 2021

CVE-2021-30606 is a use-after-free vulnerability in Chromium's Blink rendering engine that allows remote attackers to execute arbitrary code or cause denial of service via crafted web content. This af...

CVE-2021-30608

HIGH CVSS 8.8 Sep 3, 2021

CVE-2021-30608 is a use-after-free vulnerability in Chromium's Web Share API that allows remote attackers to execute arbitrary code or cause a denial of service via a crafted HTML page. This affects a...

CVE-2021-30610

HIGH CVSS 8.8 Sep 3, 2021

This vulnerability is a use-after-free flaw in Chromium's Extensions API that allows remote attackers to execute arbitrary code or cause a denial of service via a crafted HTML page. It affects all Chr...

CVE-2021-30612

HIGH CVSS 8.8 Sep 3, 2021

CVE-2021-30612 is a use-after-free vulnerability in WebRTC component of Chromium-based browsers. It allows remote attackers to execute arbitrary code or cause denial of service via crafted web content...

CVE-2021-30614

HIGH CVSS 8.8 Sep 3, 2021

This is a heap buffer overflow vulnerability in Chromium's TabStrip component that allows attackers to execute arbitrary code or cause denial of service. It affects all Chromium-based browsers includi...

CVE-2021-30616

HIGH CVSS 8.8 Sep 3, 2021

CVE-2021-30616 is a use-after-free vulnerability in Chromium's media component that allows remote attackers to execute arbitrary code or cause denial of service via a crafted HTML page. This affects a...

CVE-2021-30618

HIGH CVSS 8.8 Sep 3, 2021

CVE-2021-30618 is an inappropriate implementation vulnerability in Chromium's DevTools that could allow remote code execution. It affects Chromium-based browsers including Google Chrome and Microsoft ...

CVE-2021-30620

HIGH CVSS 8.8 Sep 3, 2021

CVE-2021-30620 is a high-severity vulnerability in Chromium's Blink rendering engine where insufficient policy enforcement could allow attackers to bypass security restrictions. This affects all Chrom...

CVE-2021-30622

HIGH CVSS 8.8 Sep 3, 2021

This vulnerability is a use-after-free flaw in Chromium's WebApp installation component that allows attackers to execute arbitrary code or cause a denial of service. It affects all Chromium-based brow...

CVE-2021-26411

HIGH CVSS 8.8 Mar 11, 2021

CVE-2021-26411 is a memory corruption vulnerability in Internet Explorer that allows remote attackers to execute arbitrary code on affected systems. It is exploited by tricking users into viewing mali...

CVE-2020-1568

HIGH CVSS 7.5 Aug 17, 2020

CVE-2020-1568 is a remote code execution vulnerability in Microsoft Edge PDF Reader that allows attackers to execute arbitrary code by tricking users into opening malicious PDF files. This affects use...

CVE-2019-1140

HIGH CVSS 8.8 Aug 14, 2019

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by tricking users into visiting malicious websites. It affect...

CVE-2025-62224

MEDIUM CVSS 5.5 Jan 7, 2026

This vulnerability in Microsoft Edge for Android allows an attacker to spoof user interface elements, potentially tricking users into revealing sensitive information or performing unintended actions. ...

CVE-2025-49736

MEDIUM CVSS 4.3 Aug 12, 2025

A spoofing vulnerability in Microsoft Edge for Android allows attackers to trick users into performing unintended actions via network-based deception. This affects all Android users running vulnerable...

CVE-2025-49755

MEDIUM CVSS 4.3 Aug 12, 2025

This CVE describes a UI spoofing vulnerability in Microsoft Edge for Android where an attacker can manipulate the browser interface to display misleading information. Attackers can trick users into be...

CVE-2025-25001

MEDIUM CVSS 4.3 Apr 4, 2025

This cross-site scripting (XSS) vulnerability in Microsoft Edge allows attackers to inject malicious scripts into web pages, enabling them to spoof content and potentially steal user data. It affects ...

CVE-2025-21253

MEDIUM CVSS 5.3 Feb 6, 2025

Microsoft Edge for iOS and Android contains a spoofing vulnerability that could allow an attacker to display misleading content in the browser interface. This affects users of Microsoft Edge mobile ap...

CVE-2024-38222

MEDIUM CVSS 6.5 Sep 12, 2024

This vulnerability in Microsoft Edge (Chromium-based) allows an attacker to potentially access sensitive information from the browser's memory or processes. It affects users running vulnerable version...

CVE-2024-38208

MEDIUM CVSS 6.1 Aug 22, 2024

This vulnerability in Microsoft Edge for Android allows attackers to spoof content in the browser's address bar, potentially tricking users into believing they're on a legitimate website when they're ...

CVE-2024-38156

MEDIUM CVSS 6.1 Jul 19, 2024

This vulnerability allows attackers to spoof content in Microsoft Edge by manipulating how the browser displays certain URLs. It affects users of Microsoft Edge (Chromium-based) who visit malicious we...

CVE-2024-38093

MEDIUM CVSS 4.3 Jun 20, 2024

This vulnerability in Microsoft Edge allows attackers to spoof UI elements, potentially tricking users into interacting with malicious content. It affects users of Microsoft Edge (Chromium-based) on W...

CVE-2020-1180

MEDIUM CVSS 4.2 Sep 11, 2020

This is a remote code execution vulnerability in the ChakraCore JavaScript engine that allows attackers to execute arbitrary code with the privileges of the current user. It affects systems running ap...

CVE-2020-0878

MEDIUM CVSS 4.2 Sep 11, 2020

This is a memory corruption vulnerability in Microsoft browsers that allows remote code execution. Attackers can exploit it by tricking users into visiting malicious websites, potentially gaining the ...

CVE-2019-1192

MEDIUM CVSS 4.3 Aug 14, 2019

This CVE describes a Same-Origin Policy bypass vulnerability in Microsoft browsers that allows attackers to force browsers to send cross-origin data that should be restricted. It affects users of Micr...

CVE-2019-1196

MEDIUM CVSS 4.2 Aug 14, 2019

This is a remote code execution vulnerability in Microsoft Edge's Chakra JavaScript engine that allows attackers to execute arbitrary code by tricking users into visiting malicious websites. It affect...

CVE-2019-1131

MEDIUM CVSS 4.2 Aug 14, 2019

CVE-2019-1131 is a memory corruption vulnerability in Microsoft Edge's Chakra JavaScript engine that allows remote code execution. Attackers can exploit it by tricking users into visiting malicious we...