Impact
A use‑after‑free flaw in Microsoft Edge (Chromium‑based) allows an unauthorized attacker to trigger memory corruption. The flaw permits execution of arbitrary code in the Edge process, potentially compromising user data or enabling malicious actions within the browser. The weakness is a classic use‑after‑free error (CWE‑416).
Affected Systems
All users who have installed any build of the Chromium‑based Microsoft Edge on supported operating systems are potentially affected. The advisory does not list affected versions, so it is unclear which specific releases contain the flaw; version information is currently unavailable.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity, while the EPSS score of < 1 % indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. To exploit the flaw, an attacker must deliver crafted data to Edge over the network – the exact point of entry is not detailed, but it could involve a network‑based payload directed at Edge. Once the memory error is triggered, code can run with the privileges of the Edge process.
OpenCVE Enrichment