Impact
A race condition occurs when concurrent execution accesses a shared resource without proper synchronization in Microsoft Edge (Chromium-based). This flaw, identified as CWE‑362, allows an authorized local user to read data that should otherwise be protected. Based on the description, it is inferred that an attacker cannot gain arbitrary code execution or privilege escalation from this vulnerability, so the impact remains confined to local information disclosure.
Affected Systems
Microsoft Edge (Chromium-based) is the product affected. The advisory should refer to the Microsoft update guide or the provided link to determine whether their Edge installation has received the update that addresses the race condition. All users running Edge (Chromium-based) that have not applied the latest security update may be vulnerable.
Risk and Exploitability
The CVSS score of 4.2 indicates a medium severity, and the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA KEV, implying it is a local attack that requires an authorized user or malware running in the user’s context. Exploitation would involve triggering the race condition through concurrent access to the shared resource information to the attacker.
OpenCVE Enrichment