Impact
A use‑after‑free flaw in Microsoft Edge (Chromium‑based) allows an attacker to execute arbitrary code within the browser process. The vulnerability, identified as CWE‑416, can be leveraged over a network connection, providing remote code execution capabilities to an unauthorized attacker.
Affected Systems
Microsoft Edge (Chromium‑based) installations that have not yet received the latest Microsoft update are vulnerable. No specific version ranges are provided, so any current build that lacks the applied security patch may be impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity issue. An EPSS score of less than 1% suggests that, as of the latest data, the probability of exploitation in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely by an adversary who can communicate with the victim’s browser, making it a significant risk in environments where the browser is exposed to untrusted networks.
OpenCVE Enrichment