Back to All Articles
Security
SECURITY ALERT: 94 Chromium CVEs in Cursor and Windsurf Expose 1.8 Million Developers
EndOfCoding
2026-06-01•10 min read

OX Security published a critical research report today: Cursor and Windsurf — two of the most popular AI coding IDEs, collectively used by an estimated 1.8 million developers — contain 94 unpatched Chromium vulnerabilities in their embedded browsers. These aren't theoretical risks. Chromium CVEs at this severity level include remote code execution, privilege escalation, and credential theft vectors. If you use Cursor or Windsurf, this affects you right now.
Author

EndOfCoding
No bio available.
Learning Tip
"Try applying the concepts from this article in your next project. Practice is the best way to solidify your understanding!"
Table of Contents
Ready to Start Your Vibe Coding Journey?
Apply what you've learned and create your first project using natural language programming.


