CVE-2025-29815

CWE-416Use After Free4 documents4 sources
Severity
7.6HIGH
EPSS
1.4%
top 19.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateApr 8

Description

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:LExploitability: 2.1 | Impact: 5.5

Affected Packages2 packages

CVEListV5microsoft/microsoft_edge_(chromium-based)1.0.0.0134.0.3124.66
NVDmicrosoft/edge_chromium< 134.0.3124.66

🔴Vulnerability Details

2
CVEList
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability2025-04-04
GHSA
GHSA-qf96-xw5w-6qv3: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network2025-04-04

📋Vendor Advisories

1
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability2025-04-08
CVE-2025-29815 (HIGH CVSS 7.6) | Use after free in Microsoft Edge (C | cvebase.io