CVE-2025-5925124.09.2025, 19:15Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityCode InjectionEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.6 HIGHNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:LmicrosoftCNA7.6 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L/RC:CCISA-ADPADP------Awaiting analysisThis vulnerability is currently awaiting analysis.Base ScoreCVSS 3.xEPSS ScorePercentile: UnknownCommon Weakness EnumerationCWE-94 - Improper Control of Generation of Code ('Code Injection')The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59251