Impact
An origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. This flaw enables an attacker to make the browser believe that a network resource is trusted when it is not, potentially leading to phishing, credential theft, or other attacks that rely on spoofed identities. The vulnerability is classified as CWE‑346, indicating an insecurity in how the origin of a resource is verified. The CVSS score of 5.4 indicates a moderate severity, primarily impacting confidentiality and integrity through impersonation rather than granting arbitrary code execution.
Affected Systems
Microsoft Edge (Chromium-based) as supplied by Microsoft. No specific version range is listed in the current advisory, so all currently supported releases of this browser are potentially impacted.
Risk and Exploitability
An EPSS score of 0.00216 indicates a very low probability of exploitation, showing that no large‑scale exploit campaigns have been observed. Nevertheless, the origin validation flaw can be exploited via network traffic that an Edge instance processes, meaning a remote attacker who can influence the traffic or supply crafted network packets could trigger the spoofing behavior. The moderate CVSS score reflects the potential damage to user identity assurance, but there are no known privileges or capabilities beyond the spoofed identity that are currently promised by the description.
OpenCVE Enrichment