
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62223 is a UI misrepresentation vulnerability (CWE-451) in Microsoft Edge for iOS that allows an unauthenticated network attacker to perform spoofing attacks. The vulnerability was disclosed on December 4, 2025, as part of Microsoft's December 2025 Patch Tuesday release. It affects Microsoft Edge (Chromium-based) versions prior to 143.0.3650.66. It carries a CVSS v3.1 base score of 4.3 (Medium) (MSRC Advisory, ENISA EUVD).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning the browser fails to accurately display security-critical information — such as the origin or identity of a web page — to the user. This allows an attacker to craft a malicious network resource that, when visited by a victim, is misrepresented in the Edge for iOS UI, enabling spoofing of trusted content or phishing pages. Exploitation requires user interaction (e.g., visiting a malicious link) but no privileges or authentication on the attacker's part (MSRC Advisory, ENISA EUVD). No public proof-of-concept exploit code has been identified.
Successful exploitation results in a low-integrity impact with no confidentiality or availability consequences, as reflected in the CVSS score. An attacker can deceive users into believing they are interacting with a legitimate website or trusted content when they are not, facilitating phishing, credential harvesting, or social engineering attacks. The scope is limited to the affected iOS device and does not enable lateral movement or direct data exfiltration by itself (MSRC Advisory, ENISA EUVD).
There is no evidence of active in-the-wild exploitation or public proof-of-concept code for CVE-2025-62223. The EPSS score is approximately 0.05%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (MSRC Advisory, Feedly).
Microsoft has released a patch addressing this vulnerability in Microsoft Edge (Chromium-based) version 143.0.3650.66 and later. Users and administrators should update Microsoft Edge for iOS to version 143.0.3650.66 or higher via the Apple App Store or enterprise mobile device management (MDM) solutions. No configuration-based workarounds have been published; upgrading to the patched version is the recommended remediation (MSRC Advisory, December 2025 Release Notes).
CVE-2025-62223 was covered as part of broader December 2025 Patch Tuesday roundups by security outlets including BleepingComputer, The Hacker News, Rapid7, Sophos, and Zero Day Initiative, though it received minimal individual attention given its medium severity rating. Coverage focused primarily on the three zero-days and more critical vulnerabilities addressed in the same update cycle (BleepingComputer, ZDI Review, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."