Impact
This vulnerability arises from improper neutralization of user input when Microsoft Edge (Chromium‑based) constructs web pages, creating a cross‑site scripting weakness classified as CWE‑79. An attacker can inject malicious content that modifies the DOM presented to the user, resulting in spoofed page appearance. The flaw permits an unauthorized party to display false information to a user while they view a site, thereby enabling spoofing over the network.
Affected Systems
All Microsoft Edge (Chromium‑based) installations are potentially vulnerable; the CVE does not specify a particular version range, so any current installation may be affected.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, while an EPSS score of less than 1% signals a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a malicious or compromised web page that delivers crafted script content to a user’s browser, allowing the attacker to alter the displayed page. Exploitation requires user interaction with such content and is limited to browsers that have not yet been patched.
OpenCVE Enrichment