Security Update Advisory for Microsoft Edge Browser (Version 149.0.4022.96)
Overview
Microsoft has released a security update to address vulnerabilities in Microsoft Edge (Chromium-based). This update applies to versions prior to 149.0.4022.96, And users should update to the latest version.
Resolved Vulnerabilities
The following vulnerabilities have been fixed:
- CVE-2026-13038, a critical-rated memory free-and-use vulnerability in Autofill.
- CVE-2026-13022, a critical-rated vulnerability due to improper feature implementation in Autofill.
- CVE-2026-13036 and CVE-2026-13031, critical-rated memory free-and-use vulnerabilities occurring in Blink (the browser rendering engine).
- CVE-2026-13033, a critical-rated out-of-bounds read vulnerability in Blink>InterestGroups.
- CVE-2026-13035, a critical-rated memory deallocation and reuse vulnerability in Bluetooth.
- CVE-2026-13021, a critical-rated vulnerability involving improper feature implementation in DeviceBoundSessionCredentials.
- CVE-2026-13026, a critical-rated memory deallocation and reuse vulnerability in Digital Credentials.
- CVE-2026-13027, a critical-level memory free-and-use vulnerability in FileSystem.
- CVE-2026-12032, an improper implementation vulnerability in Passwords; CVE-2026-12442, a memory deallocation and reuse vulnerability in Passwords; and CVE-2026-13034, a critical-level improper implementation vulnerability in Passwords.
- CVE-2026-12030, a vulnerability due to improper feature implementation in Views.
- CVE-2026-13025, a Critical-rated vulnerability due to insufficient validation of untrusted input in DevTools (Developer Tools).
- CVE-2026-13024, a Critical-rated vulnerability due to insufficient validation of untrusted input in Navigation.
- CVE-2026-11647, a memory deallocation and reuse vulnerability in Printing.
- CVE-2026-13023 and CVE-2026-12469, critical-severity uninitialized use vulnerabilities in the GPU (Graphics Processing Unit), and CVE-2026-12028, a use-after-free vulnerability.
- CVE-2026-13029, a critical-rated memory deallocation and reuse vulnerability in Web Authentication.
- CVE-2026-12438 and CVE-2026-12448, which are vulnerabilities related to improper feature implementation in WebView.
Action Required
Vulnerability Patches were released through the June 27, 2026, update. Users should either use Windows Update’s automatic installation feature or download and install the patches by referring to the URL provided in the product information.