Impact
External control of file name or path in Microsoft Edge (Chromium‑based) enables an attacker to read sensitive files or directories, exposing confidential data over the network. The flaw originates from insufficient validation of file references, classified as CWE‑73. Successful exploitation could lead to non‑authorization obtaining of system or user data with potential confidentiality impact.
Affected Systems
Microsoft Edge (Chromium‑based) on all affected Windows installations. No specific version range is listed, so all releases prior to the fix are potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.4, indicating a high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, so there is no confirmed exploitation evidence. The attack vector is likely remote, achievable by prompting the user to visit a malicious web page or load a crafted payload that manipulates the file path parameter. Given the moderate to high severity, the risk to organizations remains significant if the browser remains unpatched.
OpenCVE Enrichment