Impact
An information‑exposure flaw in Microsoft Edge (Chromium-based) permits an attacker to spoof a trusted party over a network, enabling the reading of data that should be protected. The issue, identified as CWE‑200, does not grant code execution or privilege escalation but can expose sensitive information such as cookies, credentials, or local content, thereby violating user confidentiality.
Affected Systems
All unpatched builds of Microsoft Edge (Chromium-based) are affected; no specific version range has been published, so any release that does not yet include the official fix remains at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderately severe vulnerability, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is a network‑based spoofing attempt—such as a malicious webpage or DNS manipulation that tricks the browser into treating an untrusted resource as legitimate. If successful, the attacker can read sensitive data from the user’s session without achieving code‑execution or privilege‑escalation.
OpenCVE Enrichment