Impact
The vulnerability in Microsoft Edge ( a use‑after‑free that, if successfully exploited, allows an attacker with authorized network access to execute arbitrary code within the Edge process. The flaw is classified as CWE‑416, indicating a failure to properly free and manage memory. By exploiting this condition, an attacker can gain full control of the system running the browser, potentially leading to disclosure, modification, or disruption of data and services.
Affected Systems
All current releases of Microsoft Edge (Chromium‑based) on Microsoft Windows and other supported operating systems are potentially affected. No specific product versions are listed in the available data, so the vulnerability applies broadly until an official patch is released by Microsoft.
Risk and Exploitability
The CVSS score of 8.3 reflects a high severity scenario for remote code execution. The EPSS score of less than 1 % indicates a very low, but non‑zero, likelihood of exploitation observed in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must be able to connect to the target system with authorized network access to Edge; the attack vector is inferred to be network‑based, exploiting memory corruption via the use‑after‑free condition.
OpenCVE Enrichment