Oct 2025: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-60711 Published on October 31, 2025

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Vendor Advisory NVD

Weakness Type

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. This weakness covers three distinct situations. A "missing" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An "insufficient" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an "ignored" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in some code path.


Products Associated with CVE-2025-60711

Want to know whenever a new CVE is published for Microsoft Edge Chromium? stack.watch will email you.

 

Affected Versions

Microsoft Edge (Chromium-based):

Exploit Probability

EPSS
0.15%
Percentile
34.88%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.