Description
Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to cause denial of service, execute arbitrary code, spoof user interface.
Below is a complete list of vulnerabilities:
- Out of bounds read vulnerability in Web Speech can be exploited to cause denial of service.
- Use after free vulnerability in WebMIDI can be exploited to cause denial of service or execute arbitrary code.
- Policy enforcement vulnerability in DevTools can be exploited to cause denial of service.
- Inappropriate implementation in V8 can be exploited to cause denial of service or execute arbitrary code.
- Policy enforcement vulnerability in Clipboard can be exploited to cause denial of service.
- Heap buffer overflow vulnerability in WebML can be exploited to cause denial of service.
- Policy enforcement vulnerability in PDF can be exploited to cause denial of service.
- A spoofing vulnerability in Microsoft Edge (Chromium-based) for Android can be exploited remotely to spoof user interface.
- Use after free vulnerability in TextEncoding can be exploited to cause denial of service or execute arbitrary code.
- Use after free vulnerability in Extensions can be exploited to cause denial of service or execute arbitrary code.
- Security UI vulnerability in LookalikeChecks can be exploited to spoof user interface.
- Policy enforcement vulnerability in ChromeDriver can be exploited to cause denial of service.
- Use after free vulnerability in WebMCP can be exploited to cause denial of service or execute arbitrary code.
- Security UI vulnerability in WebAppInstalls can be exploited to spoof user interface.
- Heap buffer overflow vulnerability in Skia can be exploited to cause denial of service.
- Use after free vulnerability in WebView can be exploited to cause denial of service or execute arbitrary code.
- Security UI vulnerability in PictureInPicture can be exploited to spoof user interface.
- Use after free vulnerability in MediaStream can be exploited to cause denial of service or execute arbitrary code.
- Heap buffer overflow vulnerability in ResourceTiming can be exploited to cause denial of service.
- Out of bounds read vulnerability in V8 can be exploited to cause denial of service.
- Heap buffer overflow vulnerability in Navigation can be exploited to cause denial of service.
- Use after free vulnerability in Agents can be exploited to cause denial of service or execute arbitrary code.
- Integer overflow vulnerability in WebML can be exploited to cause execute arbitrary code and denial of service.
- Security UI vulnerability in Downloads can be exploited to spoof user interface.
- Use after free vulnerability in WindowDialog can be exploited to cause denial of service or execute arbitrary code.
- Policy enforcement vulnerability in Extensions can be exploited to cause denial of service.
- Out of bounds memory access vulnerability in WebML can be exploited to cause denial of service.
Original advisories
- CVE-2026-3923
- CVE-2026-3941
- CVE-2026-3910
- CVE-2026-3938
- CVE-2026-3915
- CVE-2026-3932
- CVE-2026-0385
- CVE-2026-3921
- CVE-2026-3913
- CVE-2026-3919
- CVE-2026-3939
- CVE-2026-3925
- CVE-2026-3934
- CVE-2026-3918
- CVE-2026-3935
- CVE-2026-3931
- CVE-2026-3936
- CVE-2026-3942
- CVE-2026-3922
- CVE-2026-3929
- CVE-2026-3940
- CVE-2026-3926
- CVE-2026-3930
- CVE-2026-3927
- CVE-2026-3917
- CVE-2026-3914
- CVE-2026-3937
- CVE-2026-3924
- CVE-2026-3928
- CVE-2026-3920
Exploitation
Public exploits exist for this vulnerability.
Related products
CVE list
- CVE-2026-3913 critical
- CVE-2026-3914 critical
- CVE-2026-3915 critical
- CVE-2026-3916 critical
- CVE-2026-3917 critical
- CVE-2026-3918 critical
- CVE-2026-3919 critical
- CVE-2026-3920 critical
- CVE-2026-3921 critical
- CVE-2026-3922 critical
- CVE-2026-3923 critical
- CVE-2026-3924 critical
- CVE-2026-3925 warning
- CVE-2026-3926 critical
- CVE-2026-3927 warning
- CVE-2026-3928 unknown
- CVE-2026-3929 warning
- CVE-2026-3930 unknown
- CVE-2026-3931 critical
- CVE-2026-3932 unknown
- CVE-2026-3934 unknown
- CVE-2026-3935 unknown
- CVE-2026-3936 critical
- CVE-2026-3937 unknown
- CVE-2026-3938 unknown
- CVE-2026-3939 unknown
- CVE-2026-3940 unknown
- CVE-2026-3941 warning
- CVE-2026-3942 warning
- CVE-2026-3910 critical
- CVE-2026-0385 warning
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!