Spoofing attack in Microsoft Edge for iOS and Microsoft Edge for Android - CVE-2025-21253
Published: February 7, 2025
Vulnerability identifier: #VU103693
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-21253
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can spoof the page content and gain access to sensitive information.
Affected software
Microsoft Edge for iOS
Microsoft Edge for Android
Microsoft Edge for Android
How to mitigate CVE-2025-21253
Install updates from vendor's website.
Microsoft Edge for iOS - update to 133.0.3065.51
Microsoft Edge for Android - update to 133.0.3065.51
Microsoft Edge for Android - update to 133.0.3065.51