Impact
Microsoft Edge (Chromium-based) contains an improper authorization flaw that lets an attacker bypass a built‑in security feature. The vulnerability, identified as CWE-285, allows a malicious actor to trigger functionality that should only be available after proper authorization, thereby enabling unauthorized actions within the browser context.
Affected Systems
The affected product is Microsoft Edge (Chromium-based) by Microsoft. No specific version ranges are listed, so all currently supported builds are considered potentially affected until a vendor patch is released.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score of less than 1% suggests a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be over a network, where crafted traffic can reach the Edge process and exploit the missing authorization check.
OpenCVE Enrichment