Impact
The vulnerability, identified as CWE‑288, grants an attacker the ability to bypass Edge’s standard authentication by exploiting an alternate path or channel, allowing them to tamper with the browser over a network. This authentication bypass means the attacker can manipulate Edge’s state or execute actions that should be restricted, compromising data integrity and potentially other security controls.
Affected Systems
Microsoft Edge (Chromium-based) is impacted. No specific version information is disclosed in the advisory, so all installations of the Chromium-based Edge that have not been patched by Microsoft may be vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the description references an alternate authentication path, the likely attack vector is remote over the network, but no explicit exploitation instructions are provided in the advisory.
OpenCVE Enrichment