Impact
Microsoft Edge (Chromium-based) is vulnerable to an information disclosure flaw that allows an unauthorized attacker to read files or directories that should be protected. The flaw arises from insufficient access control on Edge’s local file handling, allowing exposed resources to be accessed over a network. The weakness is classified as CWE‑552 (Access Control).
Affected Systems
The vulnerability affects Microsoft Edge (Chromium-based) on all installations prior to the security update described by Microsoft. No specific version range is listed, so all versions before the update may be impacted.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability. The vulnerability is not in the CISA KEV catalog. An attacker can exploit it from a remote network location to disclose files or directories that should otherwise be restricted. The attack appears to involve remote network access, but no privilege escalation or personal user interaction is described.
OpenCVE Enrichment