Impact
A use‑after‑free flaw in Microsoft Edge (Chromium‑based) allows an attacker with sufficient network access to trigger the deallocation of memory that is still in use. This flaw permits execution of arbitrary code in the Edge process, potentially giving the attacker full control over the browser and, if privilege escalation occurs, the underlying host system. The weakness is a classic use‑after‑free error (CWE‑416).
Affected Systems
All users who have installed any build of the Chromium‑based Microsoft Edge on supported operating systems are potentially affected. The advisory does not limit the issue to specific release numbers, implying that every installed version may contain the vulnerability until an updated release is available.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity, while the EPSS score of < 1 % indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. To exploit the flaw, an attacker must deliver crafted data to Edge over the network – the exact point of entry is not detailed in the advisory, but it is inferred that the attack vector involves a network‑based payload directed at Edge. Once the memory error is triggered, code can run with the privileges of the Edge process.
OpenCVE Enrichment