Impact
A use‑after‑free flaw in Microsoft Edge (Chromium‑based) allows an attacker to execute arbitrary code within the browser process. The vulnerability, classified as CWE‑416, can be exploited over a network connection, granting an unauthorized attacker remote code execution capabilities while the Edge process is running.
Affected Systems
All Microsoft Edge (Chromium‑based) installations that have not yet received the latest security update are vulnerable. No specific version ranges are provided in the advisory, so any build lacking the applied patch may be impacted.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high severity issue. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered remotely via a network connection, it poses a significant risk in environments where the browser is exposed to untrusted networks.
OpenCVE Enrichment