CVE-2025-21267

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Feb 6, 2025
Updated: Feb 11, 2025
CWE ID 358

Summary

CVE-2025-21267 is a new spoofing vulnerability affecting Microsoft Edge, which is based on Chromium. Hackers can manipulate the display of webpages to deceive users into believing they are interacting with a legitimate site. This issue, while not allowing unauthorized access, can undermine user confidence and lead to unintentional data disclosure. Microsoft has acknowledged the vulnerability and is working on a patch to address it. Until then, users are advised to exercise caution when accessing sensitive information online and keep their web browsers updated.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Edge Chromium

Affected Vendors

  • Microsoft