[CIVN-2025-0222] Multiple Vulnerabilities in Microsoft Edge
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Microsoft Edge
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Microsoft Edge versions prior to 140.0.3485.81
Overview
Multiple vulnerabilities have been reported in Microsoft Edge, which could allow a remote attacker to bypass security restrictions and execute arbitrary code on the targeted system.
Target Audience:
All end-user organisations and individuals using Microsoft Edge.
Risk Assessment:
High risk of remote code execution.
Impact Assessment:
Potential for unauthorized data access or service disruption.
Description
Microsoft Edge (Chromium-based) is a web browser developed by Microsoft using the Chromium engine, offering fast performance, enhanced security, and compatibility with modern web standards while integrating with Microsoft services.
Multiple vulnerabilities exist in Microsoft Edge due to use-after-free in Dawn and WebRTC, type confusion in V8, and Heap buffer overflow in ANGLE. A remote attacker could exploit these vulnerabilities via specially crafted web content.
Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restrictions and execute arbitrary code on the targeted system.
Note: CVE-2025-10585 is being actively exploited in the wild.
Solution
Apply appropriate updates as mentioned by the vendor:
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-18-2025
References
Microsoft
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-18-2025
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10500
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10501
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10502
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10585
CVE Name
CVE-2025-10500
CVE-2025-10501
CVE-2025-10502
CVE-2025-10585
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjVV9oACgkQ3jCgcSdc
ys+fTw/8CsAgxvdqqKqhQqhnApmkmpqGvUchWIBUNYaJKGfq+FF+/3TU2dOpeIyx
AvUfo9pLEwGc+ifqsa0lEpqiXmELnEUxdyNVXnrlT3cAvZ6Fy5b0FsUJPoGWMcAk
7TD/nLOvP7obX5TzfIGzMtd3jG07VWpcBB+QPmOK/zvMhS0buFVxwJoY3Q8yADeA
l8eeqqj+ixIhqy42/lzonoHtmU/aI7aQx/VXIKRA/33pB0V6onehX4096JV0Y0Iu
ZCeKET2dXmkMk9wNXX/5K+icSgv6f833FSM5NUALV0/ijlntMEH/M9YUeDwaCNR/
2deBWucfkfPuAMZvdiF8FX+XDDFxACJXp5kwCyfpR3VkPKdCJSw9Gg0zkpAQKP03
9KtsVNaAwWqay1AZ2Lb+CdNUQllv5cxVPbC1WhaXc7anhi9N+W+wKxxMf6HN5gUe
wyEzUSsY1MdvTJMVdnw8KhJrdECZUy4Gz5OnSlmHE5LQKovOxTTF3Jekfn54e5Wq
uSzHkQDp4CHF9YObHCkpGf3wXFxerNbHYdO4t/cpi9hdJmjAdSxzpCk8CwgNo/K9
T+kZhravBAbn6gNklbesOaddnEiyvxGCK+NQIpHRQFNyQWDFWFALn9dusvfnRPq/
kEv9m5Ee4KfoxuZso++NzI7UQ0AZLhr7IdqKNECzzvqr5zgBam4=
=Ce7D
—–END PGP SIGNATURE—–