CVE-2025-47964: Microsoft Edge (Chromium-based) Spoofing Vulnerability

Overview

Severity
Medium (CVSS 5.4)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
Category
Edge - Chromium
Exploit Status
Not Exploited
Patch Tuesday
2025-Jun
Released
2025-06-26
EPSS Score
0.27% (percentile: 50.6%)

FAQ

How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. Additionally, an attacker could convince a local user to open a malicious file. The attacker would have to convince the user to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file. According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability? The Edge browser's tab-splitting feature, which allows users to browse two tabs simultaneously, only displays the domain prefix in the address bars instead of the full URL. This behavior can lead to phishing vulnerabilities, as attackers could exploit it to make malicious websites appear legitimate by mimicking trusted domain names. What is the version information for this release? Microsoft Edge Version Date Released Based on Chromium Version 138.0.3351.55 6/26/2025 138.0.7204.49/.50

Affected Products (1)

Browser

  • Microsoft Edge (Chromium-based)

Acknowledgments

<a href="https://www.linkedin.com/in/barathstalin/">Barath Stalin K</a>

Revision History

  • 2025-06-26: Information published.