CVE-2025-25000
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-25000 is a type confusion vulnerability affecting Microsoft Edge, the Chromium-based web browser. This issue allows an unauthorized attacker to gain unauthorized code execution over a network by accessing a resource using an incompatible type. Type confusion occurs when a program interprets data of one type as another type, leading to unexpected behavior and potential security breaches. In this case, the vulnerability can be exploited to execute malicious code, posing a significant risk to users browsing the web. Microsoft is encouraged to release a patch as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Edge
Affected Vendors
- Microsoft