CVE-2026-11287
Insufficient validation of untrusted input in Navigation in Microsoft Edge vulnerability
MSRC advisory June 9, 2026
Alert details
- Source feed
- Microsoft MSRC
- CVE ID
- CVE-2026-11287
- Affected products
- Microsoft Edge · Microsoft Microsoft Edge · Microsoft
What happened
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
What it means for your business
Insufficient validation of untrusted input in Navigation in Microsoft Edge vulnerability (CVE-2026-11287) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Sources
Related briefs
Heap buffer overflow in ANGLE in Microsoft Edge vulnerability
Heap buffer overflow in ANGLE in Microsoft Edge vulnerability (CVE-2025-10502) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Out of bounds write in V8 in Microsoft Edge vulnerability
Out of bounds write in V8 in Microsoft Edge vulnerability (CVE-2026-4450) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Type Confusion in V8 in Microsoft Edge vulnerability
Type Confusion in V8 in Microsoft Edge vulnerability (CVE-2025-2135) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Out of bounds memory access in V8 in Microsoft Edge vulnerability
Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.