Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2025-65046: Microsoft Edge (Chromium-based) Spoofing Vulnerability

According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N), some loss of integrity (I:L) but have no effect on availability (A:N). What is the impact of this vulnerability?

An attacker using either a specially-crafted page or a content script injected into a target page can show an extension’s popup over a permission prompt or screen share dialog allowing the extension to spoof parts of the prompt’s UI that shows its origin.

Microsoft Security Response Center
#vulnerability#microsoft#chrome#Microsoft Edge (Chromium-based)#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2025-14766: Chromium: CVE-2025-14766 Use after free in WebGPU