Description
Multiple vulnerabilities were found in Microsoft Browser. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, gain privileges, obtain sensitive information, spoof user interface.
Below is a complete list of vulnerabilities:
- A remote code execution vulnerability in Chromoting can be exploited remotely to execute arbitrary code.
- Security vulnerability can be exploited to bypass security restrictions.
- A remote code execution vulnerability in DOM can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Network can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Dawn can be exploited remotely to execute arbitrary code.
- A spoofing vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to spoof user interface.
- A remote code execution vulnerability in WebGL can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in DevTools can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in V8 can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Compositing can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in Skia can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in Compositing can be exploited remotely to cause denial of service.
- Denial of service vulnerability in CrashReporting can be exploited remotely to cause denial of service.
- Information disclosure vulnerability in CacheStorage can be exploited to obtain sensitive information.
- An elevation of privilege vulnerability in Microsoft Edge (Chromium-based) can be exploited remotely to gain privileges.
- Denial of service vulnerability in V8 can be exploited remotely to cause denial of service.
Original advisories
- CVE-2026-85051
- CVE-2026-85049
- CVE-2026-85052
- CVE-2026-85045
- CVE-2026-84333
- CVE-2026-85043
- CVE-2026-76017
- CVE-2026-76018
- CVE-2026-84330
- CVE-2026-77490
- CVE-2026-85042
- CVE-2026-76021
- CVE-2026-76036
- CVE-2026-76039
- CVE-2026-76022
- CVE-2026-85053
- CVE-2026-76019
- CVE-2026-76023
- CVE-2026-84352
- CVE-2026-85048
- CVE-2026-85892
- CVE-2026-87536
Exploitation
Public exploits exist for this vulnerability.
Related products
CVE list
- CVE-2026-76036 critical
- CVE-2026-76039 high
- CVE-2026-76017 critical
- CVE-2026-76018 critical
- CVE-2026-76019 critical
- CVE-2026-76021 critical
- CVE-2026-76022 critical
- CVE-2026-76023 critical
- CVE-2026-84330 high
- CVE-2026-84333 critical
- CVE-2026-84352 critical
- CVE-2026-85042 critical
- CVE-2026-85043 critical
- CVE-2026-85045 critical
- CVE-2026-85048 critical
- CVE-2026-85049 critical
- CVE-2026-85051 critical
- CVE-2026-85052 warning
- CVE-2026-85053 critical
- CVE-2026-87491 critical
- CVE-2026-87536 unknown
- CVE-2026-77490 high
- CVE-2026-85892 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!