Description
Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, spoof user interface.
Below is a complete list of vulnerabilities:
- Denial of service vulnerability in ANGLE can be exploited remotely to cause denial of service.
- Denial of service vulnerability in GPU can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in WebAppInstalls can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Autofill can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Core can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Input can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in SurfaceCapture can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in Accessibility can be exploited remotely to cause denial of service.
- Denial of service vulnerability in WebView can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in WebShare can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Serial can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in Payments can be exploited remotely to cause denial of service.
- Denial of service vulnerability in Drag and Drop can be exploited remotely to cause denial of service.
- Denial of service vulnerability in Tab Group Sync can be exploited remotely to cause denial of service.
- Denial of service vulnerability in Custom Tabs can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in ANGLE can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in WebView can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in Dawn can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in GPU can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in NFC can be exploited remotely to cause denial of service.
- Denial of service vulnerability in WebAPKs can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Geolocation can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Messages can be exploited remotely to execute arbitrary code.
- Security UI vulnerability in Contact Picker can be exploited to spoof user interface.
- Security UI vulnerability in Messages can be exploited to spoof user interface.
- Security vulnerability in WebView can be exploited to bypass security restrictions.
- A remote code execution vulnerability in USB can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in Cronet can be exploited remotely to cause denial of service.
- Security vulnerability in PreviewTab can be exploited to bypass security restrictions.
- Security vulnerability in CustomTabs can be exploited to bypass security restrictions.
- Security vulnerability in WebAuthentication can be exploited to bypass security restrictions.
- Denial of service vulnerability in UI can be exploited remotely to cause denial of service.
- Denial of service vulnerability in CustomTabs can be exploited remotely to cause denial of service.
- Denial of service vulnerability in Navigation can be exploited remotely to cause denial of service.
- Security vulnerability in Android Autofill can be exploited to bypass security restrictions.
- Denial of service vulnerability in Reader Mode can be exploited remotely to cause denial of service.
Original advisories
- CVE-2026-10892
- CVE-2026-10923
- CVE-2026-10929
- CVE-2026-10934
- CVE-2026-10953
- CVE-2026-10959
- CVE-2026-10967
- CVE-2026-10984
- CVE-2026-11007
- CVE-2026-11010
- CVE-2026-11012
- CVE-2026-11019
- CVE-2026-11029
- CVE-2026-11034
- CVE-2026-11035
- CVE-2026-11045
- CVE-2026-11064
- CVE-2026-11065
- CVE-2026-11072
- CVE-2026-11077
- CVE-2026-11080
- CVE-2026-11082
- CVE-2026-11097
- CVE-2026-11108
- CVE-2026-11119
- CVE-2026-11127
- CVE-2026-11131
- CVE-2026-11145
- CVE-2026-11148
- CVE-2026-11163
- CVE-2026-11167
- CVE-2026-11172
- CVE-2026-11175
- CVE-2026-11178
- CVE-2026-11188
- CVE-2026-11215
- CVE-2026-11226
- CVE-2026-11247
- CVE-2026-11263
- CVE-2026-11270
- CVE-2026-11278
- CVE-2026-11287
- CVE-2026-11290
- CVE-2026-11291
- CVE-2026-11295
- CVE-2026-11297
Exploitation
Public exploits exist for this vulnerability.
Related products
CVE list
- CVE-2026-10883 critical
- CVE-2026-10892 critical
- CVE-2026-10923 critical
- CVE-2026-10929 critical
- CVE-2026-10934 critical
- CVE-2026-10953 critical
- CVE-2026-10959 critical
- CVE-2026-10967 critical
- CVE-2026-10984 high
- CVE-2026-11007 high
- CVE-2026-11010 critical
- CVE-2026-11012 critical
- CVE-2026-11019 high
- CVE-2026-11029 critical
- CVE-2026-11034 high
- CVE-2026-11035 high
- CVE-2026-11045 high
- CVE-2026-11064 high
- CVE-2026-11065 critical
- CVE-2026-11072 critical
- CVE-2026-11077 critical
- CVE-2026-11080 critical
- CVE-2026-11082 critical
- CVE-2026-11097 high
- CVE-2026-11108 critical
- CVE-2026-11119 critical
- CVE-2026-11127 high
- CVE-2026-11131 critical
- CVE-2026-11145 high
- CVE-2026-11148 high
- CVE-2026-11163 critical
- CVE-2026-11167 critical
- CVE-2026-11172 critical
- CVE-2026-11175 critical
- CVE-2026-11178 warning
- CVE-2026-11188 critical
- CVE-2026-11215 high
- CVE-2026-11226 high
- CVE-2026-11247 warning
- CVE-2026-11263 high
- CVE-2026-11270 high
- CVE-2026-11278 high
- CVE-2026-11287 high
- CVE-2026-11290 warning
- CVE-2026-11291 warning
- CVE-2026-11295 critical
- CVE-2026-11297 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!