[CIVN-2025-0206] Multiple Vulnerabilities in Microsoft Edge (Chromium-based)
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Microsoft Edge (Chromium-based)
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Microsoft Edge (Chromium based) version prior to 140.0.3485.54
Overview
Multiple vulnerabilities have been reported in Microsoft Edge (Chromium based), which could allow an attacker to bypass security restrictions and execute arbitrary code on the targeted system.
Target Audience:
All end-user organizations and individuals using Microsoft Edge (Chromium based).
Risk Assessment:
High risk of unauthorized access to data and system compromise.
Impact Assessment:
Bypass security restrictions and remote code execution.
Description
Microsoft Edge (Chromium-based) is a web browser developed by Microsoft using the Chromium engine, offering fast performance, enhanced security, and compatibility with modern web standards while integrating with Microsoft services.
Multiple vulnerabilities exist in Microsoft Edge (Chromium based) due to use-after-free in V8, improper implementation in Toolbar, Extensions, and Downloads and bypass the Security feature on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker bypass security restrictions and execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-5-2025
References
Microsoft
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-5-2025
CVE Name
CVE-2025-53791
CVE-2025-9864
CVE-2025-9865
CVE-2025-9866
CVE-2025-9867
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjBhkIACgkQ3jCgcSdc
ys9I7hAAgR+dHTbO1Smnn6sCYsojvtZsPWDOKn/KBGIHyK9cC8nwMeEvWHE/N+w6
h/TEmrTm1+qhzxlMgRYr160jebyugoUGbSdjsQqdw/lps9Mg772yIg7LxDbQRJYm
ax3bpdDb1XdPLhOJJynDnrbXhMFWUtNmb7jG91+8XXL1QhGQ3tZrWFkIw/lOU+Mi
Iv2Y+Wukj4qAXKRH0dEuaBUsn7rdznXB/PDMbhmFQX2IdGTUoTvJ4PyXagagJQHm
RoHyZuNI58hN1C+zCf6t8KAkLjkZY2kzrUnaxpW9TIG839qWfcAwBNJD2m/Tck7+
pbbG/2/K27frVogFxJcboUQX+N/kKToscoZqbI9kaGo8aTfc1PPPuTffD2fjgnFg
iiP6cOSp0oqndbaJdcRwHWab8A5iBoNfTJvHKDyf0CX2bC5D3yeIXY37xMPYREw9
cRjmmW6NDlwzRbveRYm0X/t2V/d453E14dhVDwesULS1Tvfjn/jFOUlrvcRCPx4i
BYNYlyeV40TbJ3K6kDhboYFqGQxHv+pZzPLfkum2SsmltnVpB9K2bBaaGV1Wugd7
ja2A4kGHE+7BJIHWKrdKYDyhTwTjdLvdnvKdPiia7Z//mVqDmwb8DcJLgafdRe5a
KULAcbWKTMecF4cgZvZ4cP4DYbmzlI6TZjqHbSGtcTAnQ80wtUo=
=oybQ
—–END PGP SIGNATURE—–