Microsoft has released Edge Stable Channel Version 138.0.3351.65, an update that addresses critical browser vulnerabilities impacting Chromium-based Microsoft Edge. The patch includes fixes for two high-severity flawsβone of which is already being exploited in the wild, and the other involving remote code execution (RCE) triggered via crafted user interaction.
Tired of noisy Microsoft CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysReported by the Chromium security team and actively exploited, CVE-2025-6554 is a type confusion vulnerability in the V8 JavaScript engine that powers both Google Chrome and Microsoft Edge. In essence, this flaw allows a malicious website to manipulate memory boundaries, enabling the attacker to read or write arbitrary memory locations. This could lead to sandbox escape, information theft, or even full remote code executionβdepending on how the vulnerability is chained.
In addition to the Chromium fix, Microsoft has addressed CVE-2025-49713, a Microsoft Edgeβspecific vulnerability with a CVSS score of 8.8. This flaw allows an attacker to execute remote code if they can convince a user to click a malicious link or open a compromised attachment.
βThis attack requires an authenticated client to click a link so that an unauthenticated attacker can initiate remote code execution,β Microsoft explains.
The attack scenario mirrors social engineering techniques: the attacker sends a phishing email, instant message, or document designed to lure the user into loading a malicious site. Once the bait is taken, the attacker can execute arbitrary code on the victimβs machineβpotentially installing malware, stealing credentials, or pivoting within a corporate network.
Related Posts:
- Actively Exploited Google Chrome Zero-Day (CVE-2025-6554) Added to CISAβs KEV Catalog, PoC Available
- Google exposes a Microsoft Edge browser flaw
- Chrome Update Alert: Two High-Severity Flaws Patched β Update Now to Stay Safe!
- Microsoft Edge for Android: Extension Support Finally Arrives
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!