Microsoft Edge users faced a series of serious vulnerabilities spanning remote code execution, information disclosure, and legacy browser compatibility risks. Reported issues included CVE-2025-59251, an Edge remote code execution flaw with limited public technical detail; CVE-2025-29834, an out-of-bounds read in the V8 JavaScript engine affecting versions before 135.0.2789.91; and CVE-2025-49713, a type confusion bug in V8 that reportedly enabled in-the-wild exploitation against Edge versions before 138.0.3351.65. Separately, CVE-2025-49741 was described as an information disclosure issue tied to improper validation of the x-middleware-subrequest HTTP header, potentially exposing cached data and session tokens in versions before 137.0.3296.62.
The disclosures also highlighted risk beyond standard browsing sessions. CVE-2025-30397 affected Microsoft’s Scripting Engine when Edge was used in Internet Explorer Mode, creating an actively exploited path to remote code execution on Windows 10 and Windows 11 systems that still depend on legacy web applications. Microsoft issued updates across the affected products, while defenders were urged to prioritize browser patching, review exposure in Chromium-based deployments, harden JavaScript and web-content controls, and reduce or disable IE Mode where operationally possible. A new advisory from HKCERT on multiple Microsoft Edge vulnerabilities underscores the continuing volume of security issues affecting the browser.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
HKCERT published a product advisory titled "Microsoft Edge Multiple Vulnerabilities." The provided reference includes no synopsis, so no additional event details are available from the source content.
CVE-2025-59251, a remote code execution vulnerability in Chromium-based Microsoft Edge with a CVSS score of 7.6, was disclosed and documented in the Microsoft Security Update Guide. Public sources cited in the content did not provide technical root cause details, affected version ranges, or exploitation methods.
Microsoft released an Edge security update for CVE-2025-49713, a type confusion vulnerability affecting versions before 138.0.3351.65. The source says exploitation is reportedly occurring in the wild, although the patch section appears to reference a different CVE.
Microsoft released a security update for CVE-2025-49741, described in the source as an information disclosure vulnerability affecting Edge versions prior to 137.0.3296.62. The report urges users to apply the update promptly, though it contains internal inconsistencies about the affected component.
Microsoft released Windows patches KB5058405 for Windows 10 and KB5058411 for Windows 11 to address CVE-2025-30397, a type confusion vulnerability in the Microsoft Scripting Engine affecting Edge Internet Explorer Mode. The source describes the flaw as actively exploited and particularly risky for enterprises relying on legacy web applications.
Microsoft released an update for Chromium-based Edge addressing CVE-2025-29834, an out-of-bounds read flaw affecting versions prior to 135.0.2789.91. The source states no public detection methods or indicators of compromise were provided at the time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
hkcert.org
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.