Wednesday, 09 July 2025

Multiple Vulnerabilities in Microsoft Edge Could Allow for Arbitrary Code Execution

Microsoft Edge is a Chromium based internet browser made by Microsoft, which is installed by default on all new Windows computers. Multiple vulnerabilities have been discovered in Microsoft Edge, the most severe of which could result in remote code execution. Vulnerabilities affect Microsoft Edge (Chromium-based) prior to 94.0.992.31 version. Details of the vulnerabilities are as follows:

  • Use after free vulnerability – CVE-2021-37956;

  • Use after free vulnerability in WebGPU – CVE-2021-37957;

  • Inappropriate implementation vulnerability in Navigation – CVE-2021-37958;

  • Use after free vulnerability in Task Manager – CVE-2021-37959;

  • Inappropriate implementation vulnerability in Blink graphics – CVE-2021-37960;

  • Use after free vulnerability in Tab Strip – CVE-2021-37961;

  • Use after free vulnerability in Performance Manager – CVE-2021-37962;

  • Side-channel information leakage vulnerability in DevTools – CVE-2021-37963;

  • Inappropriate implementation vulnerability in ChromeOS Networking – CVE-2021-37964;

  • Inappropriate implementation vulnerability in Background Fetch API – CVE-2021-37965;

  • Inappropriate implementation vulnerability in Compositing – CVE-2021-37966;

  • Inappropriate implementation vulnerability in Background Fetch API – CVE-2021-37967;

  • Inappropriate implementation vulnerability in Background Fetch API – CVE-2021-37968;

  • Inappropriate implementation vulnerability in Google Updater – CVE-2021-37969;

  • Use after free vulnerability in File System API – CVE-2021-37970;

  • Incorrect security UI vulnerability in Web Browser UI – CVE-2021-37971;

  • Out of bounds read vulnerability in libjpeg-turbo – CVE-2021-37972;

  • Use after free vulnerability in Portals - CVE-2021-37973.

01 October 2021

-
136