Msrc Microsoft Edge vulnerabilities
1,721 known vulnerabilities affecting msrc/microsoft_edge.
Total CVEs
1,721
CISA KEV
58
actively exploited
Public exploits
16
Exploited in wild
48
Severity breakdown
CRITICAL66HIGH965MEDIUM659LOW24UNKNOWN7
Vulnerabilities
Page 10 of 87
CVE-2025-12431MEDIUMCVSS 6.52025-10-14
CVE-2025-12431 [MEDIUM] Chromium: CVE-2025-12431 Inappropriate implementation in Extensions
Chromium: CVE-2025-12431 Inappropriate implementation in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.3595.53
10/31/2025
142
msrc
CVE-2025-12440MEDIUMCVSS 5.32025-10-14
CVE-2025-12440 [MEDIUM] Chromium: CVE-2025-12440 Inappropriate implementation in Autofill
Chromium: CVE-2025-12440 Inappropriate implementation in Autofill
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.3595.53
10/31/2025
142.0.7
msrc
CVE-2025-11210MEDIUMCVSS 5.42025-10-14
CVE-2025-11210 [MEDIUM] Chromium: CVE-2025-11210 Side-channel information leakage in Tab
Chromium: CVE-2025-11210 Side-channel information leakage in Tab
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is
msrc
CVE-2025-12433MEDIUMCVSS 4.32025-10-14
CVE-2025-12433 [MEDIUM] Chromium: CVE-2025-12433 Inappropriate implementation in V8
Chromium: CVE-2025-12433 Inappropriate implementation in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.3595.53
10/31/2025
142.0.7445.59/.60
msrc
CVE-2025-12446MEDIUMCVSS 4.22025-10-14
CVE-2025-12446 [MEDIUM] Chromium: CVE-2025-12446 Incorrect security UI in SplitView
Chromium: CVE-2025-12446 Incorrect security UI in SplitView
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.3595.53
10/31/2025
142.0.7445.59/.60
msrc
CVE-2025-11212MEDIUMCVSS 6.32025-10-14
CVE-2025-11212 [MEDIUM] Chromium: CVE-2025-11212 Inappropriate implementation in Media
Chromium: CVE-2025-11212 Inappropriate implementation in Media
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is con
msrc
CVE-2025-12434MEDIUMCVSS 4.22025-10-14
CVE-2025-12434 [MEDIUM] Chromium: CVE-2025-12434 Race in Storage
Chromium: CVE-2025-12434 Race in Storage
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.3595.53
10/31/2025
142.0.7445.59/.60
FAQ: Why is this Chrome CVE included
msrc
CVE-2025-12445MEDIUMCVSS 6.52025-10-14
CVE-2025-12445 [MEDIUM] Chromium: CVE-2025-12445 Policy bypass in Extensions
Chromium: CVE-2025-12445 Policy bypass in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.3595.53
10/31/2025
142.0.7445.59/.60
FAQ: Why is t
msrc
CVE-2025-12439MEDIUMCVSS 5.52025-10-14
CVE-2025-12439 [MEDIUM] Chromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption
Chromium: CVE-2025-12439 Inappropriate implementation in App-Bound Encryption
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
142.0.35
msrc
CVE-2025-11219LOWCVSS 3.12025-10-14
CVE-2025-11219 [LOW] Chromium: CVE-2025-11219 Use after free in V8
Chromium: CVE-2025-11219 Use after free in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-bas
msrc
CVE-2025-10585CRITICALCVSS 9.8KEV2025-09-09
CVE-2025-10585 [CRITICAL] Chromium: CVE-2025-10585 Type Confusion in V8
Chromium: CVE-2025-10585 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2025-10585 exists in the wild.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
msrc
CVE-2025-10890CRITICALCVSS 9.12025-09-09
CVE-2025-10890 [CRITICAL] Chromium: CVE-2025-10890 Side-channel information leakage in V8
Chromium: CVE-2025-10890 Side-channel information leakage in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.94
09/25/2025
140.0.733
msrc
CVE-2025-10200HIGHCVSS 8.82025-09-09
CVE-2025-10200 [HIGH] Chromium: CVE-2025-10200 Use after free in Serviceworker
Chromium: CVE-2025-10200 Use after free in Serviceworker
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.66
09/11/2025
140.0.7339.133
FAQ: Why i
msrc
CVE-2025-10891HIGHCVSS 8.82025-09-09
CVE-2025-10891 [HIGH] Chromium: CVE-2025-10891 Integer overflow in V8
Chromium: CVE-2025-10891 Integer overflow in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.94
09/25/2025
140.0.7339.208
FAQ: Why is this Chrome CVE
msrc
CVE-2025-10201HIGHCVSS 8.82025-09-09
CVE-2025-10201 [HIGH] Chromium: CVE-2025-10201 Inappropriate implementation in Mojo
Chromium: CVE-2025-10201 Inappropriate implementation in Mojo
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.66
09/11/2025
140.0.7339.133
msrc
CVE-2025-10502HIGHCVSS 8.82025-09-09
CVE-2025-10502 [HIGH] Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.81
09/19/2025
140.0.7339.186
FAQ: Why is th
msrc
CVE-2025-10501HIGHCVSS 8.82025-09-09
CVE-2025-10501 [HIGH] Chromium: CVE-2025-10501 Use after free in WebRTC
Chromium: CVE-2025-10501 Use after free in WebRTC
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.81
09/19/2025
140.0.7339.186
FAQ: Why is this Chrome
msrc
CVE-2025-9866HIGHCVSS 8.82025-09-09
CVE-2025-9866 [HIGH] Chromium: CVE-2025-9866 Inappropriate implementation in Extensions
Chromium: CVE-2025-9866 Inappropriate implementation in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which i
msrc
CVE-2025-59251HIGHCVSS 7.62025-09-09
CVE-2025-59251 [HIGH] CWE-121 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.81
09/19/2025
140.0.7339.186
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code executi
msrc
CVE-2025-10892HIGHCVSS 8.82025-09-09
CVE-2025-10892 [HIGH] Chromium: CVE-2025-10892 Integer overflow in V8
Chromium: CVE-2025-10892 Integer overflow in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
140.0.3485.94
09/25/2025
140.0.7339.208
FAQ: Why is this Chrome CVE
msrc