Microsoft has released Edge Stable 85.0.564.63 on September 23. The update is notable for resolving seven vulnerabilities in the browser, which are actually shared with Google Chrome. Microsoft had to issue a new browser version to get them resolved, as they are already resolved in Google's product.
The following vulnerabilities were resolved in Microsoft Edge Stable 85.0.564.63
CVE-2020-15960
Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2020-15961
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVE-2020-15962
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2020-15963
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVE-2020-15964
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-15965
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2020-15966
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
Microsoft Edge is now a Chromium-based browser with a number of exclusive features like Read Aloud and services tied to Microsoft instead of Google. The browser has already received a few updates, with support for ARM64 devices in Edge Stable 80. Also, Microsoft Edge is still supporting a number of aging Windows versions, including Windows 7, which has recently reached its end of support. Check out Windows Versions Supported by Microsoft Edge Chromium and Edge Chromium latest roadmap. Finally, interested users can download MSI installers for deployment and customization.
For pre-release versions, Microsoft is currently using three channels to deliver updates to Edge Insiders. The Canary channel receives updates daily (except Saturday and Sunday), the Dev channel is getting updates weekly, and the Beta channel is updated every 6 weeks. Microsoft is going to support Edge Chromium on Windows 7, 8.1 and 10, alongside macOS, upcoming Linux and mobile apps on iOS and Android. Windows 7 users will receive updates until July 15, 2021.
Actual Edge Versions
- Stable Channel: 85.0.564.63
- Beta Channel: 86.0.622.19
- Dev Channel: 87.0.644.4
- Canary Channel: 87.0.650.0
Download Microsoft Edge
You can download pre-release Edge version for Insiders from here:
Download Microsoft Edge Insider Preview
The stable version of the browser is available on the following page:
Download Microsoft Edge Stable
Note: Microsoft has started delivering Microsoft Edge to users of Windows via Windows Update. The update is provisioned for users of Windows 10 version 1803 and above, and replaces the classic Edge app once installed. The browser, when delivered with KB4559309, makes it impossible to uninstall it from Settings. Check out the following workaround: Uninstall Microsoft Edge If Uninstall Button is Grayed Out
Support us
Winaero greatly relies on your support. You can help the site keep bringing you interesting and useful content and software by using these options: