Skip to main content
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryactively-exploited-vulnerabilityidentity-authentication-vulnerability

Multiple Microsoft Edge Flaws Expose Users to RCE, Data Theft, and IE Mode Attacks

Updated 4d agoFirst seen Jun 12, 20266 sources

Microsoft Edge users faced a series of serious vulnerabilities spanning remote code execution, information disclosure, and legacy browser compatibility risks. Reported issues included CVE-2025-59251, an Edge remote code execution flaw with limited public technical detail; CVE-2025-29834, an out-of-bounds read in the V8 JavaScript engine affecting versions before 135.0.2789.91; and CVE-2025-49713, a type confusion bug in V8 that reportedly enabled in-the-wild exploitation against Edge versions before 138.0.3351.65. Separately, CVE-2025-49741 was described as an information disclosure issue tied to improper validation of the x-middleware-subrequest HTTP header, potentially exposing cached data and session tokens in versions before 137.0.3296.62.

The disclosures also highlighted risk beyond standard browsing sessions. CVE-2025-30397 affected Microsoft’s Scripting Engine when Edge was used in Internet Explorer Mode, creating an actively exploited path to remote code execution on Windows 10 and Windows 11 systems that still depend on legacy web applications. Microsoft issued updates across the affected products, while defenders were urged to prioritize browser patching, review exposure in Chromium-based deployments, harden JavaScript and web-content controls, and reduce or disable IE Mode where operationally possible. A new advisory from HKCERT on multiple Microsoft Edge vulnerabilities underscores the continuing volume of security issues affecting the browser.

Share:
Multiple Microsoft Edge Flaws Expose Users to RCE, Data Theft, and IE Mode Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 16, 20264d ago

HKCERT publishes Microsoft Edge multiple vulnerabilities advisory

HKCERT published a product advisory titled "Microsoft Edge Multiple Vulnerabilities." The provided reference includes no synopsis, so no additional event details are available from the source content.

Microsoft Edge Multiple Vulnerabilities
Sep 24, 20259mo ago

CVE-2025-59251 disclosed for Microsoft Edge

CVE-2025-59251, a remote code execution vulnerability in Chromium-based Microsoft Edge with a CVSS score of 7.6, was disclosed and documented in the Microsoft Security Update Guide. Public sources cited in the content did not provide technical root cause details, affected version ranges, or exploitation methods.

Microsoft Edge CVE-2025-59251 Remote Code Execution Vulnerability: Brief Summary and Technical Review - ZeroPath Blog | ZeroPath
Jul 2, 20251y ago

Microsoft releases Edge update for CVE-2025-49713 amid reported exploitation

Microsoft released an Edge security update for CVE-2025-49713, a type confusion vulnerability affecting versions before 138.0.3351.65. The source says exploitation is reportedly occurring in the wild, although the patch section appears to reference a different CVE.

Microsoft Edge Under Attack: Unpacking CVE-2025-49713's Type Confusion Exploit - ZeroPath Blog | ZeroPath
Jul 1, 20251y ago

Microsoft releases Edge update for CVE-2025-49741

Microsoft released a security update for CVE-2025-49741, described in the source as an information disclosure vulnerability affecting Edge versions prior to 137.0.3296.62. The report urges users to apply the update promptly, though it contains internal inconsistencies about the affected component.

Microsoft Edge CVE-2025-49741: Critical Information Disclosure via Middleware Bypass - ZeroPath Blog | ZeroPath
May 13, 20251y ago

Microsoft releases patches for CVE-2025-30397

Microsoft released Windows patches KB5058405 for Windows 10 and KB5058411 for Windows 11 to address CVE-2025-30397, a type confusion vulnerability in the Microsoft Scripting Engine affecting Edge Internet Explorer Mode. The source describes the flaw as actively exploited and particularly risky for enterprises relying on legacy web applications.

Type Confusion Strikes Again: Analyzing CVE-2025-30397 in Microsoft's Scripting Engine - ZeroPath Blog | ZeroPath
Apr 11, 20251y ago

Microsoft patches CVE-2025-29834 in Edge 135.0.2789.91

Microsoft released an update for Chromium-based Edge addressing CVE-2025-29834, an out-of-bounds read flaw affecting versions prior to 135.0.2789.91. The source states no public detection methods or indicators of compromise were provided at the time.

Edge of Danger: Unpacking CVE-2025-29834's Out-of-Bounds Read in Microsoft Edge - ZeroPath Blog | ZeroPath
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.