ISN 2025-04: Microsoft Edge Vulnerabilities

First published 4 February 2025

CVSS 3.1: 7.4 (High)

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Summary

Security vulnerabilities have been found in the Chromium-based Microsoft Edge web browser available as an App for IGEL OS. This affects the following product versions:

  • IGEL OS 12

Details

It has been discovered that Microsoft Edge contains two escalation of privilege vulnerabilities, CVE-2025-21185 (high) and CVE-2025-21399 (high).

Besides Edge-specific issues, Edge contains issues inherited from its Chromium base. These have been closed by importing the latest fixes from Chromium.

Update Instructions

  • OS 12: Update to the Microsoft Edge OS 12 app version 132.0.2957.115 or newer from the IGEL App Portal.

References