Impact
The vulnerability is an integer overflow (CWE-190) that occurs while handling certain numeric values in Microsoft Edge (Chromium-based). An attacker with network access can trigger this overflow and cause the browser to execute arbitrary code in the user’s process, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Edge (Chromium-based) is affected. No specific build or version information is disclosed, so all current installations of this browser that use the vulnerable Chromium engine should be considered at risk until a vendor patch is applied.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. Its EPSS score is reported as less than 1%, denoting a very low but non-zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalogue. The description that malicious code can be executed over a network suggests a network-based attack vector, though exact prerequisites are not specified in the CVE data.
OpenCVE Enrichment