Microsoft Edge (Chromium) < 143.0.3650.66 Multiple Vulnerabilities

high Nessus Plugin ID 277534

Synopsis

The remote host has an web browser installed that is affected by multiple vulnerabilities.

Description

The version of Microsoft Edge installed on the remote Windows host is prior to 143.0.3650.66. It is, therefore, affected by multiple vulnerabilities as referenced in the December 4, 2025 advisory.

- Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low) (CVE-2025-13639)

- Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) (CVE-2025-13630)

- Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High) (CVE-2025-13631)

- Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High) (CVE-2025-13632)

- Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
(Chromium security severity: High) (CVE-2025-13633)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Microsoft Edge version 143.0.3650.66 or later.

See Also

http://www.nessus.org/u?f90821a2

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13630

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13631

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13632

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13633

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13634

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13635

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13636

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13637

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13638

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13639

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13640

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13720

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13721

Plugin Details

Severity: High

ID: 277534

File Name: microsoft_edge_chromium_143_0_3650_66.nasl

Version: 1.1

Type: local

Agent: windows

Family: Windows

Published: 12/5/2025

Updated: 12/5/2025

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2025-13639

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:microsoft:edge

Required KB Items: SMB/Registry/Enumerated, installed_sw/Microsoft Edge (Chromium)

Exploit Ease: No known exploits are available

Patch Publication Date: 12/4/2025

Vulnerability Publication Date: 12/2/2025

Reference Information

CVE: CVE-2025-13630, CVE-2025-13631, CVE-2025-13632, CVE-2025-13633, CVE-2025-13634, CVE-2025-13635, CVE-2025-13636, CVE-2025-13637, CVE-2025-13638, CVE-2025-13639, CVE-2025-13640, CVE-2025-13720, CVE-2025-13721