Kaspersky ID:
KLA91090
Detect Date:
06/09/2026
Updated:
06/15/2026

Description

Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. Denial of service vulnerability in ANGLE can be exploited remotely to cause denial of service.
  2. Denial of service vulnerability in GPU can be exploited remotely to cause denial of service.
  3. A remote code execution vulnerability in WebAppInstalls can be exploited remotely to execute arbitrary code.
  4. A remote code execution vulnerability in Autofill can be exploited remotely to execute arbitrary code.
  5. A remote code execution vulnerability in Core can be exploited remotely to execute arbitrary code.
  6. A remote code execution vulnerability in Input can be exploited remotely to execute arbitrary code.
  7. A remote code execution vulnerability in SurfaceCapture can be exploited remotely to execute arbitrary code.
  8. Denial of service vulnerability in Accessibility can be exploited remotely to cause denial of service.
  9. Denial of service vulnerability in WebView can be exploited remotely to cause denial of service.
  10. A remote code execution vulnerability in WebShare can be exploited remotely to execute arbitrary code.
  11. A remote code execution vulnerability in Serial can be exploited remotely to execute arbitrary code.
  12. Denial of service vulnerability in Payments can be exploited remotely to cause denial of service.
  13. Denial of service vulnerability in Drag and Drop can be exploited remotely to cause denial of service.
  14. Denial of service vulnerability in Tab Group Sync can be exploited remotely to cause denial of service.
  15. Denial of service vulnerability in Custom Tabs can be exploited remotely to cause denial of service.
  16. A remote code execution vulnerability in ANGLE can be exploited remotely to execute arbitrary code.
  17. A remote code execution vulnerability in WebView can be exploited remotely to execute arbitrary code.
  18. Denial of service vulnerability in Dawn can be exploited remotely to cause denial of service.
  19. A remote code execution vulnerability in GPU can be exploited remotely to execute arbitrary code.
  20. Denial of service vulnerability in NFC can be exploited remotely to cause denial of service.
  21. Denial of service vulnerability in WebAPKs can be exploited remotely to cause denial of service.
  22. A remote code execution vulnerability in Geolocation can be exploited remotely to execute arbitrary code.
  23. A remote code execution vulnerability in Messages can be exploited remotely to execute arbitrary code.
  24. Security UI vulnerability in Contact Picker can be exploited to spoof user interface.
  25. Security UI vulnerability in Messages can be exploited to spoof user interface.
  26. Security vulnerability in WebView can be exploited to bypass security restrictions.
  27. A remote code execution vulnerability in USB can be exploited remotely to execute arbitrary code.
  28. Denial of service vulnerability in Cronet can be exploited remotely to cause denial of service.
  29. Security vulnerability in PreviewTab can be exploited to bypass security restrictions.
  30. Security vulnerability in CustomTabs can be exploited to bypass security restrictions.
  31. Security vulnerability in WebAuthentication can be exploited to bypass security restrictions.
  32. Denial of service vulnerability in UI can be exploited remotely to cause denial of service.
  33. Denial of service vulnerability in CustomTabs can be exploited remotely to cause denial of service.
  34. Denial of service vulnerability in Navigation can be exploited remotely to cause denial of service.
  35. Security vulnerability in Android Autofill can be exploited to bypass security restrictions.
  36. Denial of service vulnerability in Reader Mode can be exploited remotely to cause denial of service.

Original advisories

Exploitation

Related products

CVE list

  • CVE-2026-10883
    critical
  • CVE-2026-10892
    critical
  • CVE-2026-10923
    critical
  • CVE-2026-10929
    critical
  • CVE-2026-10934
    critical
  • CVE-2026-10953
    critical
  • CVE-2026-10959
    critical
  • CVE-2026-10967
    critical
  • CVE-2026-10984
    high
  • CVE-2026-11007
    high
  • CVE-2026-11010
    critical
  • CVE-2026-11012
    critical
  • CVE-2026-11019
    high
  • CVE-2026-11029
    critical
  • CVE-2026-11034
    high
  • CVE-2026-11035
    high
  • CVE-2026-11045
    high
  • CVE-2026-11064
    high
  • CVE-2026-11065
    critical
  • CVE-2026-11072
    critical
  • CVE-2026-11077
    critical
  • CVE-2026-11080
    critical
  • CVE-2026-11082
    critical
  • CVE-2026-11097
    high
  • CVE-2026-11108
    critical
  • CVE-2026-11119
    critical
  • CVE-2026-11127
    high
  • CVE-2026-11131
    critical
  • CVE-2026-11145
    high
  • CVE-2026-11148
    high
  • CVE-2026-11163
    critical
  • CVE-2026-11167
    critical
  • CVE-2026-11172
    critical
  • CVE-2026-11175
    critical
  • CVE-2026-11178
    warning
  • CVE-2026-11188
    critical
  • CVE-2026-11215
    high
  • CVE-2026-11226
    high
  • CVE-2026-11247
    warning
  • CVE-2026-11263
    high
  • CVE-2026-11270
    high
  • CVE-2026-11278
    high
  • CVE-2026-11287
    high
  • CVE-2026-11290
    warning
  • CVE-2026-11291
    warning
  • CVE-2026-11295
    critical
  • CVE-2026-11297
    critical

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Do you want to save your changes?
Your message has been sent successfully.