Msrc Microsoft Edge vulnerabilities
1,721 known vulnerabilities affecting msrc/microsoft_edge.
Total CVEs
1,721
CISA KEV
58
actively exploited
Public exploits
16
Exploited in wild
48
Severity breakdown
CRITICAL66HIGH965MEDIUM659LOW24UNKNOWN7
Vulnerabilities
Page 16 of 87
CVE-2025-21267MEDIUMCVSS 4.42025-02-11
CVE-2025-21267 [MEDIUM] CWE-358 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
Additionally, an attacker could convince a local user to open a malicious file. T
msrc
CVE-2025-0996MEDIUMCVSS 5.42025-02-11
CVE-2025-0996 [MEDIUM] Chromium: CVE -2025-0996 Inappropriate implementation in Browser UI
Chromium: CVE -2025-0996 Inappropriate implementation in Browser UI
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) wh
msrc
CVE-2025-0445MEDIUMCVSS 5.42025-02-11
CVE-2025-0445 [MEDIUM] Chromium: CVE-2025-0445 Use after free in V8
Chromium: CVE-2025-0445 Use after free in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-bas
msrc
CVE-2025-21401MEDIUMCVSS 4.52025-02-11
CVE-2025-21401 [MEDIUM] CWE-601 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
133.0.3065.69
2/14/2025
133.0.6943.98/.99
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), integrity (I:L) and availabil
msrc
CVE-2025-21404MEDIUMCVSS 4.32025-02-11
CVE-2025-21404 [MEDIUM] CWE-449 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
133.0.3065.51
2/6/2025
133.0.6943.53/54
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by
msrc
CVE-2025-0451MEDIUMCVSS 6.32025-02-11
CVE-2025-0451 [MEDIUM] Chromium: CVE-2025-0451 Inappropriate implementation in Extensions API
Chromium: CVE-2025-0451 Inappropriate implementation in Extensions API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OS
msrc
CVE-2025-0998UNKNOWN2025-02-11
CVE-2025-0998 Chromium: CVE -2025-0998 Out of bounds memory access in V8
Chromium: CVE -2025-0998 Out of bounds memory access in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsof
msrc
CVE-2025-0291HIGHCVSS 8.82025-01-14
CVE-2025-0291 [HIGH] Chromium: CVE-2025-0291 Type Confusion in V8
Chromium: CVE-2025-0291 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based
msrc
CVE-2025-0762HIGHCVSS 8.82025-01-14
CVE-2025-0762 [HIGH] Chromium: CVE-2025-0762 Use after free in DevTools
Chromium: CVE-2025-0762 Use after free in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Ch
msrc
CVE-2025-0447HIGHCVSS 8.82025-01-14
CVE-2025-0447 [HIGH] Chromium: CVE-2025-0447 Inappropriate implementation in Navigation
Chromium: CVE-2025-0447 Inappropriate implementation in Navigation
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which i
msrc
CVE-2025-0437HIGHCVSS 8.82025-01-14
CVE-2025-0437 [HIGH] Chromium: CVE-2025-0437 Out of bounds read in Metrics
Chromium: CVE-2025-0437 Out of bounds read in Metrics
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Ed
msrc
CVE-2025-0611HIGHCVSS 8.22025-01-14
CVE-2025-0611 [HIGH] Chromium: CVE-2025-0612 Out of bounds memory access in V8
Chromium: CVE-2025-0612 Out of bounds memory access in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Micr
msrc
CVE-2025-0443HIGHCVSS 8.82025-01-14
CVE-2025-0443 [HIGH] Chromium: CVE-2025-0443 Insufficient data validation in Extensions
Chromium: CVE-2025-0443 Insufficient data validation in Extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which i
msrc
CVE-2025-0436HIGHCVSS 8.82025-01-14
CVE-2025-0436 [HIGH] Chromium: CVE-2025-0436 Integer overflow in Skia
Chromium: CVE-2025-0436 Integer overflow in Skia
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromi
msrc
CVE-2025-0434HIGHCVSS 8.82025-01-14
CVE-2025-0434 [HIGH] Chromium: CVE-2025-0434 Out of bounds memory access in V8
Chromium: CVE-2025-0434 Out of bounds memory access in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Micr
msrc
CVE-2025-0612HIGHCVSS 8.22025-01-14
CVE-2025-0612 [HIGH] Chromium: CVE-2025-0611 Object corruption in V8
Chromium: CVE-2025-0611 Object corruption in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium
msrc
CVE-2025-0438HIGHCVSS 8.82025-01-14
CVE-2025-0438 [HIGH] Chromium: CVE-2025-0438 Stack buffer overflow in Tracing
Chromium: CVE-2025-0438 Stack buffer overflow in Tracing
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Micros
msrc
CVE-2025-0440MEDIUMCVSS 6.52025-01-14
CVE-2025-0440 [MEDIUM] Chromium: CVE-2025-0440 Inappropriate implementation in Fullscreen
Chromium: CVE-2025-0440 Inappropriate implementation in Fullscreen
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which
msrc
CVE-2025-0435MEDIUMCVSS 6.52025-01-14
CVE-2025-0435 [MEDIUM] Chromium: CVE-2025-0435 Inappropriate implementation in Navigation
Chromium: CVE-2025-0435 Inappropriate implementation in Navigation
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which
msrc
CVE-2025-0448MEDIUMCVSS 4.32025-01-14
CVE-2025-0448 [MEDIUM] Chromium: CVE-2025-0448 Inappropriate implementation in Compositing
Chromium: CVE-2025-0448 Inappropriate implementation in Compositing
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) whi
msrc