Low CVSS 4.7 EPSS 0.00464 2025-04 archive

Executive Summary

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Overview

4.7
CVSS MEDIUM
Low
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Spoofing
Released Apr 8 2025
Last Updated Apr 8 2025
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00464 — 0.36556 percentile
NVD CVSS 4.7 MEDIUM — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:P/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Changed
CONFIDENTIALITY
None
INTEGRITY
Low
AVAILABILITY
None
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 4.2

EPSS Score

0.00464
probability of exploitation in the next 30 days
0.36556 percentile - updated 2026-06-21
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Microsoft Edge for iOS Release Notes (Security Update) Low Spoofing No

Patches

1 patch
Article Type Restart
Release Notes Security Update No

Known Exploits

Acknowledgments

Barath Stalin K