CVE-2025-60711
published 2025-10-31CVE-2025-60711: Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
PriorityP337medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.38%
30.9th percentile
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 142.0.3595.53 | 142.0.3595.53 |
| microsoft | microsoft_edge | >= 1.0.0.0 < 142.0.3595.53 | 142.0.3595.53 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
vendor_msrc·2025-10-14·CVSS 6.3
CVE-2025-60711 [MEDIUM] CWE-693 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Description: Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.3595.53
10/31/2025
142.0.7445.59/.60
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of the vulnerability requires that a user open a specially crafted file.
In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file.
In a web-based attack scenario, an attacker could host
GHSA
GHSA-mm48-wj9h-vg49: Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network
ghsa_unreviewed·2025-10-31
CVE-2025-60711 [MEDIUM] CWE-693 GHSA-mm48-wj9h-vg49: Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-31
Published