CVE-2025-25000

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 843

Summary

CVE-2025-25000 is a type confusion vulnerability affecting Microsoft Edge, the Chromium-based web browser. This issue allows an unauthorized attacker to gain unauthorized code execution over a network by accessing a resource using an incompatible type. Type confusion occurs when a program interprets data of one type as another type, leading to unexpected behavior and potential security breaches. In this case, the vulnerability can be exploited to execute malicious code, posing a significant risk to users browsing the web. Microsoft is encouraged to release a patch as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share