Multiple vulnerabilities in Microsoft Edge, including CVE-2026-3910 (CVSS 8.8), allow a remote attacker to achieve spoofing, remote code execution, and security restriction bypass. The article notes CVE-2026-3910 is being actively exploited. According to authoritative NVD data, affected versions are Google Chrome prior to 146.0.7680.75, and the fix is to update to version 146.0.7680.75 or later.
Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, remote code execution and security restriction bypass on the targeted system. Note: CVE-2026-3910 is being exploited in the wild. A... Impact Remote Code Execution Security Restriction Bypass Spoofing System / Technologies affected Microsoft Edge version prior to 146.0.3856.59 Solutions Before installation of the software, please visit the software vendor web-site for more details. Apply fixes issued by the vendor: Update to version 146.0.3856.59 or later