CVE-2025-29796
published 2025-04-04CVE-2025-29796: Microsoft Edge for iOS Spoofing Vulnerability User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized…
medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
EPSS
0.56%
43.2th percentile
Microsoft Edge for iOS Spoofing Vulnerability
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_edge_for_ios | >= 1.0.0.0 < 135.0.3179.54 | 135.0.3179.54 |
| msrc | microsoft_edge_for_ios | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
cvelistv54.7MEDIUM
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge for iOS Spoofing Vulnerability
vendor_msrc·2025-04-08·CVSS 4.7
CVE-2025-29796 [MEDIUM] CWE-451 Microsoft Edge for iOS Spoofing Vulnerability
Microsoft Edge for iOS Spoofing Vulnerability
Description: User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
A user could be tricked into entering credentials or responding to a pop up after opening a specially crafted file or clicking on a link, typically by way of an enticement in an email or URL.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
135.0.3179.54
4/3/2025
135.0.7049.41/.42/.52
FAQ: According to the CVSS metric, user interaction is required (UI:R). What int
CVEList
Microsoft Edge for iOS Spoofing Vulnerability
cvelistv5·2025-04-04·CVSS 4.7
CVE-2025-29796 [MEDIUM] CWE-451 Microsoft Edge for iOS Spoofing Vulnerability
Microsoft Edge for iOS Spoofing Vulnerability
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
No detection rules found.
No public exploits indexed.
2025-04-04
Published