🟠 High  |  Source: Microsoft Security Response Center


A vulnerability involving uninitialized memory use in the GPU component of Chromium has been assigned CVE-2026-13023 by the Chrome team. Microsoft Edge, being Chromium-based, inherits this flaw and is affected until patched. Uninitialized memory vulnerabilities can potentially be exploited to leak sensitive data or achieve arbitrary code execution within the browser process.

Security Architect’s Take: Ensure Microsoft Edge deployments across your organisation are updated to the latest version that includes the Chromium fix; if you manage browser baselines via Intune or Group Policy, trigger an expedited update cycle and verify compliance, particularly for privileged users and virtual desktop environments.

Original advisory: Chromium: CVE-2026-13023 Uninitialized Use in GPU