Microsoft Edge Security Update – 24 February 2025

Microsoft has released an updated Microsoft Edge stable channel (133.0.3065.82) to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to perform a denial of service attack or exploit heap corruption via a crafted HTML page and gain access to the affected system.

Sample of the addressed vulnerabilities:

Microsoft Edge (Chromium-based) Heap Buffer Overflow Vulnerability (CVE-2025-0999):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2025-0999
  • CVE-2025-1426
  • CVE-2025-1006
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References