Edge Stable 85.0.564.63 comes with 7 vulnerabilities fixed

Edge Stable Fluent Big 256 Icon

Microsoft has released Edge Stable 85.0.564.63  on September 23. The update is notable for resolving seven vulnerabilities in the browser, which are actually shared with Google Chrome. Microsoft had to issue a new browser version to get them resolved, as they are already resolved in Google's product.

The following vulnerabilities were resolved in Microsoft Edge Stable 85.0.564.63

CVE-2020-15960

Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVE-2020-15961

Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVE-2020-15962

Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVE-2020-15963

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVE-2020-15964

Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-15965

Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVE-2020-15966

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

Microsoft Edge is now a Chromium-based browser with a number of exclusive features like Read Aloud and services tied to Microsoft instead of Google. The browser has already received a few updates, with support for ARM64 devices in Edge Stable 80. Also, Microsoft Edge is still supporting a number of aging Windows versions, including Windows 7, which has recently reached its end of support. Check out Windows Versions Supported by Microsoft Edge Chromium and Edge Chromium latest roadmap. Finally, interested users can download MSI installers for deployment and customization.

For pre-release versions, Microsoft is currently using three channels to deliver updates to Edge Insiders. The Canary channel receives updates daily (except Saturday and Sunday), the Dev channel is getting updates weekly, and the Beta channel is updated every 6 weeks. Microsoft is going to support Edge Chromium on Windows 7, 8.1 and 10, alongside macOS, upcoming Linux and mobile apps on iOS and Android. Windows 7 users will receive updates until July 15, 2021.

Actual Edge Versions


Download Microsoft Edge

You can download pre-release Edge version for Insiders from here:

Download Microsoft Edge Insider Preview

The stable version of the browser is available on the following page:

Download Microsoft Edge Stable


Note: Microsoft has started delivering Microsoft Edge to users of Windows via Windows Update. The update is provisioned for users of Windows 10 version 1803 and above, and replaces the classic Edge app once installed. The browser, when delivered with KB4559309, makes it impossible to uninstall it from Settings. Check out the following workaround: Uninstall Microsoft Edge If Uninstall Button is Grayed Out

Support us

Winaero greatly relies on your support. You can help the site keep bringing you interesting and useful content and software by using these options:

If you like this article, please share it using the buttons below. It won't take a lot from you, but it will help us grow. Thanks for your support!

Author: Sergey Tkachenko

Sergey Tkachenko is a software developer who started Winaero back in 2011. On this blog, Sergey is writing about everything connected to Microsoft, Windows and popular software. Follow him on Telegram, Twitter, and YouTube.

Leave a Reply

Your email address will not be published.

Exit mobile version
Using Telegram? Subscribe to the blog channel!
Hello. Add your message here.