Published November 9, 2025
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202[SS9.1]5) for more information.
Published June 19, 2025
Corrected the CVE description and title. This is an informational change only.
Published June 13, 2025
Added an acknowledgement. This is an informational change only.
Published June 13, 2025
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Published June 13, 2025
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Published June 11, 2025
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Published June 10, 2025
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
Published June 10, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published June 10, 2025
Microsoft is announcing the availability of the security updates for Microsoft Office 365. Customers running Office 365 should log in ensure you have the latest update to be protected from this vulnerability. See the [Release Notes](https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates) for more information.
Published June 10, 2025
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.