Impact
This flaw arises from improper neutralization of input during web page generation, which introduces a cross‑site scripting weakness in Microsoft Edge (Chromium‑based). By injecting crafted content, an attacker can alter the browser’s DOM to display false or manipulated information, leading to spoofing over the network. The vulnerability permits attackers to mislead users about the authenticity of a web page, potentially opening the door for phishing or other social‑engineering attacks.
Affected Systems
The vulnerability applies to all Microsoft Edge (Chromium‑based) browsers; no specific version range is listed, so any current installation is potentially vulnerable.
Risk and Exploitability
A CVSS score of 7.1 reflects moderate‑to‑high severity, while an EPSS score of < 1% indicates a low likelihood of exploitation in the wild. The flaw is not currently listed in CISA’s KEV catalog. The likely attack vector is a malicious or compromised web page that delivers crafted script content to a user’s browser, enabling spoofing. Though exploitation is technically possible, attackers may opt for targeted attacks given the low EPSS score.
OpenCVE Enrichment