CVE-2025-29815
published 2025-04-04CVE-2025-29815: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
PriorityP347high7.6CVSS 3.1
AVNACLPRLUIRSUCHIHAL
EPSS
0.73%
50.3th percentile
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 134.0.3124.66 | 134.0.3124.66 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 134.0.3124.66 | 134.0.3124.66 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.17.6HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
vendor_msrc7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2025-04-08·CVSS 7.6
CVE-2025-29815 [HIGH] CWE-416 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Description: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires an authenticated client to click a link so that an unauthenticated attacker can initiate remote code execution.
FAQ: How could an attacker exploit this vulnerability via the Network?
An attacker could host a specially crafted website designed to exploit the vulnerability through Microsoft Edge and then convince a user to view the website. However, in all cases an attacker would have no way to force a user t
GHSA
GHSA-qf96-xw5w-6qv3: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-04-04
CVE-2025-29815 [HIGH] CWE-416 GHSA-qf96-xw5w-6qv3: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
2025-04-04
Published