CVE-2025-49755
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-49755 is a User Interface (UI) misrepresentation vulnerability in Microsoft Edge for Android that allows an unauthorized network attacker to perform spoofing attacks. The flaw affects Microsoft Edge for Android versions prior to 139.0.3405.86. It was disclosed and patched on August 12, 2025, as part of Microsoft's August 2025 Patch Tuesday release. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Microsoft MSRC).

Technical details

The vulnerability is classified under CWE-451 (User Interface Misrepresentation of Critical Information), meaning the browser fails to accurately represent critical security-relevant information to the user. An attacker can exploit this over a network by crafting malicious web content that causes Edge for Android to misrepresent UI elements — such as the address bar or security indicators — enabling spoofing. Exploitation requires user interaction (e.g., visiting a malicious page), but no privileges are required on the attacker's side. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC).

Impact

Successful exploitation allows an attacker to manipulate the browser's user interface, potentially tricking users into believing they are on a trusted or legitimate site when they are not. The primary impact is on integrity (CVSS integrity impact: Low), as users may be misled into disclosing credentials or sensitive information based on spoofed UI elements. There is no direct confidentiality or availability impact, and the scope is unchanged, limiting the blast radius to the affected browser session (Microsoft MSRC).

Exploitability

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2025-49755. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.038%, indicating a very low probability of exploitation in the near term. The vulnerability has not been attributed to any specific threat actor (Microsoft MSRC).

Mitigation and workarounds

Microsoft has released a patch addressing this vulnerability in Microsoft Edge for Android version 139.0.3405.86 and later. Users should update their Edge for Android browser to the latest available version via the Google Play Store. As interim guidance, users should exercise caution when interacting with unfamiliar web content, verify critical information (such as URLs and security indicators) through alternative means, and keep all browser and OS software up to date (Microsoft MSRC).

Community reactions

CVE-2025-49755 was noted as part of Microsoft's August 2025 Patch Tuesday, which addressed 107 vulnerabilities in total. Coverage was primarily aggregated in Patch Tuesday roundup articles by outlets such as BleepingComputer, Rapid7, and GBHackers, with no specific in-depth analysis dedicated to this individual CVE. Community discussion on WindowsForum highlighted the UI spoofing risk and recommended immediate updating (BleepingComputer, Rapid7, WindowsForum).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18511HIGH7.8
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18846HIGH7.5
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18509HIGH7.1
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18715MEDIUM6.5
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026
CVE-2026-18671MEDIUM5.3
  • NixOS logoNixOS
  • i
NoNoAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management