Impact
An origin validation error in Microsoft Edge (Chromium-based) allows an attacker who can send crafted network requests to read data that should be protected. The vulnerability leaks information over a communication channel, giving an unauthorized entity access to sensitive content. The flaw is classified as an information disclosure that could expose confidential data or content to the attacker.
Affected Systems
The affected product is Microsoft Edge (Chromium-based). No specific version numbers are listed, so all builds released before Microsoft’s fix may be vulnerable. Users should verify that their browser receives the latest Microsoft updates that address this issue.
Risk and Exploitability
The CVSS score of 7.4 indicates a significant risk. The EPSS score of < 1% signals a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the flaw can be triggered remotely through network traffic, meaning any host that accepts manipulated requests is potentially at risk and should monitor for anomalous traffic to Edge and apply the vendor fix as soon as it is available.
OpenCVE Enrichment