cbcvebase.
CVE-2025-49713
published 2025-07-02

CVE-2025-49713: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.68%
48.6th percentile
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftedge_chromium< 138.0.3351.65138.0.3351.65
microsoftmicrosoft_edge>= 1.0.0.0 < 138.0.3351.65138.0.3351.65
msrcmicrosoft_edge

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is a type confusion RCE in Microsoft Edge (Chromium-based); detection should focus on Edge version prior to 138.0.3351.65 making outbound network connections to attacker-controlled sites following user interaction (link click)
  • Attack vector requires user to click an attacker-supplied link; monitor for Edge processes spawning unexpected child processes or executing unusual code after navigation to external URLs
  • Attacker delivers exploit via a specially crafted website; monitor for phishing emails or instant messages containing links that redirect to external sites opened in Microsoft Edge
  • ·Exploit status is 'Publicly Disclosed: No; Exploited: No; Exploitation Unlikely' as of advisory publication — no active in-the-wild exploitation confirmed at time of disclosure

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.