Impact
A heap‑based buffer overflow in Microsoft Edge (Chromium‑based) allows an unauthorized attacker to execute arbitrary code on a compromised system. The flaw occurs when untrusted data overflows a heap buffer used by the rendering engine, providing the attacker full code‑execution privileges. Identified as CWE‑122, this weakness can be triggered by delivering malicious content over a network, giving an attacker remote access to the target device.
Affected Systems
Microsoft Edge (Chromium‑based) installations that have not received the latest security update are susceptible. The advisory does not list specific version numbers, so any instance lacking the update should be considered at risk. Earlier builds not explicitly addressed remain uncertain and may also be vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is < 1%, showing a very low but nonzero likelihood of exploitation. It is not listed in CISA KEV. Based on the description, the likely attack vector is a network attacker sending crafted data to trigger the buffer overflow, allowing remote code execution without requiring elevated privileges.
OpenCVE Enrichment