Microsoft published security advisories for a broad set of Chromium vulnerabilities affecting its browser platform, including CVE-2026-7344 (use-after-free in Accessibility), CVE-2026-7341 (use-after-free in WebRTC), CVE-2026-7353 (heap buffer overflow in Skia), and CVE-2026-7337 (type confusion in V8). Additional flaws patched include use-after-free bugs in Views, Media, GPU, Cast, and Navigation, along with insufficient validation of untrusted input in Compositing and an inappropriate implementation issue in Tint.
The volume and variety of bugs indicate a significant browser security update focused on memory-safety and input-handling weaknesses in Chromium components commonly exposed through web content. Microsoft also listed CVE-2026-31682, a separate issue tied to br_nd_send and Neighbor Discovery option parsing, but the main body of advisories centers on Chromium-derived fixes that organizations should prioritize across Microsoft Edge deployments to reduce risk from malicious websites and crafted content.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft's Security Update Guide published an advisory for CVE-2026-7980, a Chromium use-after-free vulnerability in WebAudio. The advisory represents a new Microsoft-tracked Chromium vulnerability disclosure.
Microsoft's Security Update Guide published an advisory for CVE-2026-7977, a Chromium vulnerability described as inappropriate implementation in Canvas. The advisory represents a new Microsoft-tracked Chromium vulnerability disclosure.
Microsoft's Security Update Guide published an advisory for CVE-2026-7914, a Chromium type confusion vulnerability in Accessibility. The advisory appears as a new Microsoft-tracked Chromium vulnerability disclosure.
Microsoft's Security Update Guide published a batch of Chromium-related vulnerability advisories, including CVE-2026-7333, CVE-2026-7334, CVE-2026-7335, CVE-2026-7337, CVE-2026-7338, CVE-2026-7341, CVE-2026-7343, CVE-2026-7344, CVE-2026-7346, CVE-2026-7353, CVE-2026-7356, and CVE-2026-7360. The entries cover issues such as use-after-free, type confusion, heap buffer overflow, inappropriate implementation, and insufficient validation of untrusted input across Chromium components.
Microsoft's Security Update Guide published an advisory for CVE-2026-31682, described as "bridge: br_nd_send: linearize skb before parsing ND options." The reference indicates the vulnerability entry was made public on this date.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
17 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.