Skip to main content

Microsoft Edge Multiple Vulnerabilities

Last Update Date: 16 Dec 2025 Release Date: 12 Dec 2025 19357 Views

RISK: Extremely High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.

 

Note:

CVE-2025-14174 is being exploited in the wild. The vulnerability is caused by out of bounds memory access in ANGLE which could lead to memory corruption. It allows remote attackers to trigger out-of-bounds memory access via a malicious HTML page, potentially leading to arbitrary code execution in browsers. Hence, the risk level is rated as Extremely High Risk.

 

[Updated on 2025-12-16]

Updated Description, Vulnerability Identifier, Related Links and Risk Level. 


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Microsoft Edge version prior to 143.0.3650.80

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 143.0.3650.80 or later

Vulnerability Identifier


Source


Related Link