CVE-2026-13036: Use After Free in Blink – Edge Patch

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability in the Blink rendering engine (CVE-2026-13036) has been patched by Google Chrome and inherited by Microsoft Edge, which is built on the Chromium codebase. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. This affects any environment where Microsoft Edge is deployed, including on Azure virtual machines and end-user workstations accessing cloud resources. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13035: Use After Free in Edge Bluetooth

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability in the Chromium Bluetooth component (CVE-2026-13035) has been patched by Google and is being addressed in Microsoft Edge, which is built on the Chromium engine. Use-after-free flaws occur when a programme continues to use memory after freeing it, which can allow an attacker to execute arbitrary code. This affects any Microsoft Edge deployment, including enterprise environments where Edge is used to access Azure and other cloud services. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13033: Edge Chromium Out-of-Bounds Read Fix

🟠 High | Source: Microsoft Security Response Center A vulnerability in the Blink rendering engine’s InterestGroups component has been identified as an out-of-bounds read flaw (CVE-2026-13033), originally reported via Google Chrome. Microsoft Edge, which is built on the Chromium codebase, is affected by the same issue and has ingested the upstream fix. Out-of-bounds read vulnerabilities can allow attackers to leak sensitive memory contents or potentially facilitate further exploitation. Security Architect’s Take: Ensure Microsoft Edge deployments across managed endpoints and virtual desktop environments (e.g. Azure Virtual Desktop) are updated to the latest Chromium-based build. Validate that your organisation’s browser patch cadence covers Edge as part of standard endpoint management, particularly for environments where browser-based access to cloud consoles is common. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13031: Use-After-Free in Blink & MS Edge

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability in Blink, the rendering engine used by Chromium-based browsers, has been assigned CVE-2026-13031. This flaw affects Microsoft Edge as it inherits the Chromium codebase, and use-after-free bugs in browser engines can potentially be exploited to execute arbitrary code or compromise the browser process. The fix originates from Google Chrome and is being propagated to Edge via the standard Chromium ingestion pipeline. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13029: Edge Chromium Web Auth Use-After-Free

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-13029) has been identified in the Web Authentication component of Chromium, the open-source browser engine underpinning Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. Because Microsoft Edge ingests Chromium directly, this vulnerability affects all Chromium-based Edge deployments until patched. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest patched version across all managed endpoints and virtual desktop environments — prioritise any deployments where Edge is used to access cloud management consoles or sensitive web applications. Confirm your endpoint management tooling (e.g. Intune or SCCM) has pushed the update and validate compliance via device health reporting. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13027 Use After Free in Chromium FileSystem

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-13027) has been identified in the Chromium FileSystem component, affecting Microsoft Edge and other Chromium-based browsers. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. This vulnerability was originally assigned by Google Chrome and Microsoft Edge is affected due to its Chromium dependency. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest stable release across all managed endpoints and browser fleet policies; use Intune or equivalent endpoint management tooling to enforce the update and verify compliance, paying particular attention to any cloud workstations or developer machines with elevated access to Azure environments. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13026: Chromium Use-After-Free in Edge

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-13026) has been identified in the Digital Credentials component of Chromium, affecting Microsoft Edge as a Chromium-based browser. Use-after-free flaws occur when a programme continues to use memory after it has been freed, which attackers can exploit to execute arbitrary code or cause crashes. Microsoft Edge will receive the fix via its standard Chromium ingestion process. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop deployments. Prioritise patching for users who handle sensitive credentials or operate in privileged roles, and verify that browser update policies enforced via Intune or Group Policy are functioning correctly. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13025: Chromium DevTools Input Validation Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in Chromium’s DevTools component has been identified where untrusted input is not sufficiently validated, tracked as CVE-2026-13025. Microsoft Edge, being Chromium-based, is affected and has ingested Google’s upstream fix. The flaw could potentially allow malicious content to exploit the DevTools interface, posing a risk in browser-based cloud console environments. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all engineering and operations workstations, particularly those used to access Azure Portal or other cloud consoles via browser. Consider enforcing automatic browser updates through endpoint management policies (e.g. Intune) to reduce exposure windows. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13024: Edge Chromium Navigation Input Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in Chromium’s navigation handling fails to properly validate untrusted input, potentially allowing attackers to exploit the browser through malicious web content. This affects Microsoft Edge, which is built on Chromium. The flaw has been patched by the Chrome team and the fix is being ingested into Edge. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual desktop environments — particularly relevant for Azure Virtual Desktop and enterprise browser deployments. Consider enforcing browser update policies via Intune or Group Policy to minimise the window of exposure. ...

27 June 2025 Â· ZX Cloud Security

CVE-2026-13023: Chromium GPU Flaw Affects Microsoft Edge

🟠 High | Source: Microsoft Security Response Center A vulnerability involving uninitialized memory use in the GPU component of Chromium has been assigned CVE-2026-13023 by the Chrome team. Microsoft Edge, being Chromium-based, inherits this flaw and is affected until patched. Uninitialized memory vulnerabilities can potentially be exploited to leak sensitive data or achieve arbitrary code execution within the browser process. Security Architect’s Take: Ensure Microsoft Edge deployments across your organisation are updated to the latest version that includes the Chromium fix; if you manage browser baselines via Intune or Group Policy, trigger an expedited update cycle and verify compliance, particularly for privileged users and virtual desktop environments. ...

27 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options