[CIVN-2025-0218] Multiple Vulnerabilities in Microsoft Edge
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Microsoft Edge
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Microsoft Edge version prior to 140.0.3485.66
Overview
Multiple vulnerabilities have been reported in Microsoft Edge, which could allow a remote attacker to bypass security restrictions and execute arbitrary code on the targeted system.
Target Audience:
All end-user organizations and individuals using Microsoft Edge.
Risk Assessment:
High risk of unauthorized access to data and system compromise.
Impact Assessment:
Service disruption and remote code execution.
Description
Microsoft Edge (Chromium-based) is a web browser developed by Microsoft using the Chromium engine, offering fast performance, enhanced security, and compatibility with modern web standards while integrating with Microsoft services.
Multiple vulnerabilities exist in Microsoft Edge due to Use after free in Serviceworker and Inappropriate implementation in Mojo. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted website.
Successful exploitation of these vulnerabilities could allow a remote attacker to bypass security restrictions and execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-11-2025
References
Microsoft
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#september-11-2025
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10200
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-10201
CVE Name
CVE-2025-10200
CVE-2025-10201
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmjNbbEACgkQ3jCgcSdc
ys9aVw//ee1Kbv5SaVN4WSfv8qxE73ggUPmNAa3sttR2ILnI0xVudLmt3sAL8mp2
GcpQOfxcrPJbY+h+BbmIApEQb4DkonDVldXRZmSd4tmGA+gXxmTYNBYL1S1C4JoD
lLxZe5v4SzaGsks+Gom0rSx39/H1OOXwSmHmo8oG213nv8gIu5Afh1fI3OiVcAcE
BvMdHsxfo3q0hsQysRjU8jDYfVsLddHfH8+8DbouyQ2ulDqQX78eE2kT8IvaahBF
CVg0NCh5/SLhT20/mIwcaEZpJKaeHPQd/0yBb8Htz95A+oIEupPH+vU08KL19FV2
4glGjN7RKiXvLZsSlSIG2PsV5DSiTwv34mdg8drr1iKUlj+5HwGMA5ZJmjKV6Fyb
EXChrURLooDbYWuOf49rbJrBjV5PlEhpffcfR7eVIQrADwHnYbT59sYWxlM4nOJT
b6aO/lBj7v9+9LhdJ4KLTc1EQ1qyD7rAw89DLU1l9dQp+aeWI+sQHig2/K0NHZWG
2ZrCFKpqri8NVzXWD4MPcc90wF+r9k0t3mFqoCU/btE+c+1sm6gnJlopDP5YQEnO
4iEk/yl4dMrxA7HIroDT4NQUg+ulfl+gquPrbwgYhFIGvqGhZD/Q/WqeNIKeJsfH
oK4Anj5g7dbSzYMytZFQGVWGeSZ9wgo6wIvBOGkEiEaR9o6cgTI=
=rrpQ
—–END PGP SIGNATURE—–