Description
Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Use after free vulnerability in WebGL on Android can be exploited remotely to bypass security restrictions by performing a sandbox escape.
- Uninitialized use vulnerability in GPU on Android can be exploited remotely to obtain potentially sensitive information from process memory.
- Use after free vulnerability in WebView on Android can be exploited locally to execute arbitrary code inside a sandbox.
- Use after free vulnerability in Payments can be exploited by a local attacker with physical access to potentially exploit heap corruption, causing denial of service or executing arbitrary code.
- Use after free vulnerability in AdFilter can be exploited remotely via a crafted HTML page to execute arbitrary code.
- A remote code execution vulnerability in IndexedDB can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Extensions API can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in ANGLE can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Extensions can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Views can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Ozone can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Autofill can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Codecs can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in WebAppInstalls can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Actor can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Payments can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Input can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in GetUserMedia can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Core can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in WebRTC can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in Codecs can be exploited remotely to cause denial of service.
- Denial of service vulnerability in DOM can be exploited remotely to cause denial of service.
- Security vulnerability in Passwords can be exploited to bypass security restrictions.
- Denial of service vulnerability in Forms can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in Forms can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in WebGL can be exploited remotely to cause denial of service.
- Security vulnerability in Navigation can be exploited to bypass security restrictions.
- Denial of service vulnerability in Navigation can be exploited remotely to cause denial of service.
- Denial of service vulnerability in V8 can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in InterestGroups can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in libyuv can be exploited remotely to execute arbitrary code.
Original advisories
- CVE-2026-13283
- CVE-2026-15107
- CVE-2026-15108
- CVE-2026-15109
- CVE-2026-15110
- CVE-2026-15111
- CVE-2026-15112
- CVE-2026-15113
- CVE-2026-15114
- CVE-2026-15115
- CVE-2026-15116
- CVE-2026-15117
- CVE-2026-15118
- CVE-2026-15119
- CVE-2026-15120
- CVE-2026-15121
- CVE-2026-15122
- CVE-2026-15123
- CVE-2026-15124
- CVE-2026-15125
- CVE-2026-15126
- CVE-2026-15127
- CVE-2026-15128
- CVE-2026-15129
- CVE-2026-15130
- CVE-2026-15131
- CVE-2026-15132
- CVE-2026-15133
- CVE-2026-15767
- CVE-2026-13028
- CVE-2026-13030
- CVE-2026-13032
- CVE-2026-13037
Exploitation
Related products
CVE list
- CVE-2026-13028 unknown
- CVE-2026-13030 unknown
- CVE-2026-13032 unknown
- CVE-2026-13037 unknown
- CVE-2026-13282 unknown
- CVE-2026-13283 unknown
- CVE-2026-15107 unknown
- CVE-2026-15108 unknown
- CVE-2026-15109 unknown
- CVE-2026-15110 unknown
- CVE-2026-15111 unknown
- CVE-2026-15112 unknown
- CVE-2026-15113 unknown
- CVE-2026-15114 unknown
- CVE-2026-15115 unknown
- CVE-2026-15116 unknown
- CVE-2026-15117 unknown
- CVE-2026-15118 unknown
- CVE-2026-15119 unknown
- CVE-2026-15120 unknown
- CVE-2026-15121 unknown
- CVE-2026-15122 unknown
- CVE-2026-15123 unknown
- CVE-2026-15124 unknown
- CVE-2026-15125 unknown
- CVE-2026-15126 unknown
- CVE-2026-15127 unknown
- CVE-2026-15128 unknown
- CVE-2026-15129 unknown
- CVE-2026-15130 unknown
- CVE-2026-15131 unknown
- CVE-2026-15132 unknown
- CVE-2026-15133 unknown
- CVE-2026-15767 unknown
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!