Impact
This vulnerability is a relative path traversal flaw in Microsoft Edge (Chromium-based) that permits an attacker to invoke arbitrary code execution. The weakness allows unauthorized code to be run, compromising confidentiality, integrity, and availability of the compromised system. The flaw is rooted in inadequate validation of file paths and is identified by CWE-23.
Affected Systems
Microsoft Edge (Chromium-based) – the CVE does not specify affected versions; it is unknown which releases are impacted. All current releases might be affected, but this is not confirmed.
Risk and Exploitability
The 7.1 indicates a high severity. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not currently listed in the CISA KEV. Based on the description, the likely attack vector is a remote network attack where an unauthorized attacker crafts requests that exploit the path traversal to execute code on the target system. Because the flaw does not require authentication, even low‑privileged or domain users could trigger it once network access is available.
OpenCVE Enrichment