Security Update Advisory for Microsoft Edge (Version 152.0.4191.62)

Security Update Advisory for Microsoft Edge (Version 152.0.4191.62)

Overview

Microsoft has released a security update that addresses several vulnerabilities in Microsoft Edge (Chromium-based). This update applies to versions of Microsoft Edge (Chromium-based) prior to 152.0.4191.62.

Resolved Vulnerabilities

This update addresses the following vulnerabilities:

  • A critical memory deallocation-and-reuse vulnerability in the proxy feature (CVE-2026-84324).
  • A critical memory-free-then-reuse vulnerability in the DataTransfer feature (CVE-2026-84325).
  • A critical memory-free-then-reuse vulnerability in the Shared Tab Groups feature (CVE-2026-84353).
  • A high-severity memory deallocation and reuse vulnerability in the Browser feature (CVE-2026-84349).
  • A high-severity buffer overflow vulnerability in the GPU feature (CVE-2026-84351).
  • High-severity unauthorized access vulnerability in the FileSystem feature (CVE-2026-84354).
  • High-severity improper input validation vulnerability in the Omnibox feature (CVE-2026-84357).
  • A high-severity information disclosure vulnerability in the Skia feature (CVE-2026-84359).
  • A high-severity use-of-uninitialized-resource vulnerability in the V8 feature (CVE-2026-84326).
  • Moderate-severity missing authorization vulnerability in the FileSystem feature (CVE-2026-84323).
  • Moderate-severity incorrect authorization vulnerability in the SiteSettings feature (CVE-2026-84332).
  • Medium-severity improper authorization vulnerability in the Chromoting feature (CVE-2026-84334).
  • Medium-severity improper authorization vulnerability in the TabStrip feature (CVE-2026-84335).
  • A medium-severity memory free-and-use vulnerability in the WebRTC feature (CVE-2026-84347).
  • A medium-severity information disclosure vulnerability in the MediaCapture feature (CVE-2026-84348).
  • Moderate-severity unauthorized access vulnerability in the Navigation feature (CVE-2026-84355).
  • Moderate-severity user interface display error vulnerability in the FullScreen feature (CVE-2026-84356).
  • Moderate-severity vulnerability involving improper permission management in the Downloads feature (CVE-2026-84358).
  • Low-severity vulnerability involving missing permissions in the FileSystem feature (CVE-2026-84328).
  • Low-severity confused agent vulnerability in the CredentialProvider feature (CVE-2026-84329).
  • Low-severity incorrect authorization vulnerability in the Actor feature (CVE-2026-84331).
  • A low-severity incorrect authorization vulnerability in the Autofill feature (CVE-2026-84327).
  • A low-severity use-after-free vulnerability in the TabStrip feature (CVE-2026-84350).

Recommended Action

Patches were released through the September 2, 2026, update. Users should update to Microsoft Edge (Chromium-based) version 152.0.4191.62 Or later by using Microsoft Edge’s automatic update feature or by visiting the URL provided in the product information.