🟠 High | Source: Microsoft Security Response Center
A vulnerability in Chromium’s GPU handling (CVE-2026-13030) involves the use of uninitialised memory, which can lead to unpredictable behaviour including potential code execution. Microsoft Edge, being Chromium-based, is affected and will receive the fix via Google’s upstream patch. Google Chrome Releases contains the authoritative details and remediation guidance.
Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual desktop environments — particularly relevant for Azure Virtual Desktop deployments where browser updates may lag. Validate that your endpoint management policies (e.g. via Intune or WSUS) are enforcing automatic Chromium-based browser updates.
Original advisory: Chromium: CVE-2026-13030 Uninitialized Use in GPU