Microsoft Edge browser (142.0.3595.53) version security update advisory

Microsoft Edge browser (142.0.3595.53) version security update advisory

Overview

 

Microsoft(https://www.microsoft.com) has released a security update that fixes vulnerabilities in products it has supplied. Users of affected products are advised to update to the latest version.

 

Affected Products

 

Microsoft Edge 142.0.3595.53 and earlier

Microsoft Edge (Chromium-based) 142.0.7445.59/.60 and earlier

 

Resolved Vulnerabilities

 

Improper Functional Implementation of the App-Bound Encryption feature in Microsoft Edge (Chromium-based) (CVE-2025-12439)

Improper Functional Implementation Vulnerability in the Autofill Feature in Microsoft Edge (Chromium-based) (CVE-2025-12440)

Improper Functional Implementation Vulnerability in the Extensions feature in Microsoft Edge (Chromium-based) (CVE-2025-12431)

Incorrect security UI in Fullscreen UI Vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12444)

Incorrect security UI in Omnibox vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12447, CVE-2025-12435)

Incorrect security UI in SplitView Vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12446)

Object lifecycle issue in Media vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12430)

Memory Reuse After Freeing in Ozone Functionality in Microsoft Edge (Chromium-based) (CVE-2025-12438)

Reuse After Freeing Memory Vulnerability in the PageInfo Function in Microsoft Edge (Chromium-based) (CVE-2025-12437)

Policy bypass in Extensions vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12445, CVE-2025-12436)

Race in Storage Vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12434)

Race in V8 Vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12432)

Read Out of Scope of V8 Functionality Vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12441)

Improper Functional Implementation of V8 Features Vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-12443, CVE-2025-12433, CVE-2025-12429, CVE-2025-12036)

Type Confusion Vulnerability in V8 Features in Microsoft Edge (Chromium-based) (CVE-2025-12428)

Critical remote code execution vulnerability in Microsoft Edge (Chromium-based) (CVE-2025-60711)

 

Vulnerability Patches

 

With the October 31, 2025 update, the following product-specific Vulnerability Patches were made available

 

Microsoft Edge version 142.0.3595.53

Microsoft Edge (Chromium-based) 142.0.7445.59/.60 version