Microsoft's Security Update Guide published entries for several third-party and upstream vulnerabilities affecting components used across its ecosystem, including Chromium, Git, and wolfSSH. The listed issues include CVE-2026-0628, an insufficient policy enforcement flaw in the Chromium WebView tag; CVE-2022-4135, a heap buffer overflow in Chromium's GPU component; and CVE-2025-13631, described as an inappropriate implementation issue in Google Updater.
The guide also added CVE-2025-46334, identified as a Git Malicious Shell Vulnerability, and CVE-2025-10966, which describes missing SFTP host verification with wolfSSH. Together, the entries highlight Microsoft tracking a mix of browser, developer tooling, and secure file transfer weaknesses that could affect enterprise environments through embedded or bundled software dependencies.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-0628, described as insufficient policy enforcement in the Chromium WebView tag.
Microsoft's Security Update Guide lists CVE-2025-46334 as a Git malicious shell vulnerability. No further synopsis is provided in the reference.
Microsoft published a Security Update Guide entry for CVE-2025-10966, described as missing SFTP host verification with wolfSSH.
Microsoft published a Security Update Guide entry for CVE-2025-13631, described as an inappropriate implementation issue in Google Updater within Chromium-related software.
Microsoft's Security Update Guide lists CVE-2022-4135, a Chromium heap buffer overflow in GPU. The advisory publication marks the disclosed event in the provided references.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.