Impact
Improper input validation in Microsoft Edge (Chromium‑based) allows an unauthorized attacker to execute code over a network. The flaw is classified as CWE‑20 and can cause the browser to treat malicious content as legitimate executable code, resulting in a loss of confidentiality, integrity, and availability of the affected machine.
Affected Systems
Microsoft Edge (Chromium‑based) is the only product mentioned. No specific version information is included, so all current releases of this browser are potentially affected until Microsoft releases a patch.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while the EPSS score of less than 1 % suggests that exploitation is expected to be rare at present. The vulnerability is not included in the CISA KEV catalog. Attackers can exploit the flaw by delivering malicious content to an unpatched instance of the browser over the network.
OpenCVE Enrichment