Security Update Recommendation for Microsoft Edge Browser (Version 149.0.4022.105)

Security Update Recommendation for Microsoft Edge Browser (Version 149.0.4022.105)

Microsoft Edge Security Update Advisory


Microsoft has released a security update that addresses multiple vulnerabilities in Microsoft Edge (Chromium-based). This update applies to versions prior to 150.0.4078.65.

The resolved vulnerabilities include the following: as follows:

  • A memory deallocation and reuse vulnerability in the Actor feature (CVE-2026-15116).
  • A memory deallocation and reuse vulnerability in the Autofill feature (CVE-2026-15113).
  • A memory deallocation and reuse vulnerability in the Core feature (CVE-2026-15120).
  • An integer overflow vulnerability in the Extensions API feature (CVE-2026-15108).
  • Memory deallocation and reuse vulnerability in the Extensions feature (CVE-2026-15110).
  • Memory deallocation and reuse vulnerability in the Forms feature (CVE-2026-15126).
  • Inadequate implementation vulnerabilities in the Forms feature (CVE-2026-15125, CVE-2026-15128).
  • Inadequate implementation vulnerability in the GetUserMedia feature (CVE-2026-15119).
  • Memory reuse vulnerability in the IndexedDB feature (CVE-2026-15107).
  • Memory reuse vulnerability in the Input feature (CVE-2026-15118).
  • Insufficient data validation vulnerability in the DOM feature (CVE-2026-15123).
  • Insufficient data validation vulnerability in the Navigation feature (CVE-2026-15131).
  • Insufficient validation of untrusted input in the Codecs feature (CVE-2026-15122).
  • Insufficient validation of untrusted input in the WebAppInstalls feature (CVE-2026-15115).
  • Use-after-free vulnerability in the InterestGroups feature (CVE-2026-15133).
  • Insufficient policy enforcement vulnerability in the Navigation feature (CVE-2026-15130).
  • Out-of-bounds memory read and write vulnerability in the Codecs feature (CVE-2026-15114).
  • Memory deallocation and reuse vulnerability in the Ozone feature (CVE-2026-15112).
  • Insufficient policy enforcement vulnerability in the Passwords feature (CVE-2026-15124).
  • Memory deallocation and reuse vulnerability in the Payments feature (CVE-2026-15117).
  • Use of uninitialized memory vulnerability in the ANGLE feature (CVE-2026-15109).
  • Uninitialized memory use vulnerability in the V8 feature (CVE-2026-15132).
  • Free-and-reuse vulnerability in the Views feature (CVE-2026-15129, CVE-2026-15111).
  • Vulnerability in the WebGL feature due to improper feature implementation (CVE-2026-15127).
  • Vulnerability in the WebRTC feature due to memory deallocation and reuse (CVE-2026-15121).

Some vulnerabilities are rated “High,” and the vulnerabilities in the Ozone feature, as well as some vulnerabilities in the Views feature, are classified as “Critical.” Microsoft released patches via an update on July 29, 2026.

Users should update to the latest version either through automatic installation using Windows Update or through manual installation by following the URL provided in the product information.