CVE-2025-25000: Microsoft Edge Chromium

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Affected products

  • Microsoft Edge Chromium: before 135.0.3179.54 (fixed in 135.0.3179.54)

Published 2025-04-04. Last modified 2026-06-17.