Microsoft Edge Security Update – 09 March 2025

Microsoft has released an updated Microsoft Edge stable channel “134.0.3124.51” to fix multiple vulnerabilities.

The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, obtain sensitive information through a crafted HTML page, or execute arbitrary code and gain access to the affected system by persuading the victim to install malicious extensions.

Sample of the addressed vulnerabilities:

1. Microsoft Edge (Chromium-based) Out of bounds Read Vulnerability (CVE-2025-1914):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Microsoft Edge (Chromium-based) Directory Traversal Vulnerability (CVE-2025-1915):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Information Disclosure
Vulnerabilities
  • CVE-2025-1914
  • CVE-2025-1915
  • CVE-2025-1916
  • CVE-2025-1917
  • CVE-2025-1918
  • CVE-2025-1919
  • CVE-2025-1921
  • CVE-2025-1922
  • CVE-2025-1923
  • CVE-2025-26643
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft Edge Security Update

References