Impact
This vulnerability permits an attacker to cause Microsoft Edge (Chromium-based) to display falsified security indicators or other user interface elements that misrepresent the trustworthiness of a web page. The primary impact is user deception, which can facilitate phishing attacks and other social‑engineering tactics. The weakness aligns with authorization bypass (CWE‑290) and improper filtering of UI elements (CWE‑749).
Affected Systems
Microsoft Edge (Chromium-based) is the affected product. The advisory does not specify particular builds, indicating that all current releases of the browser are potentially vulnerable. No version restrictions are listed, so administrators should assume all supported versions are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not included in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote, involving a user navigating to a malicious web page; no other prerequisites are noted.
OpenCVE Enrichment