Impact
Microsoft Edge (Chromium-based) contains an improper link resolution before file access flaw that allows an attacker to read and send the contents of local or network files over the network. The weakness, classified as CWE-59, results in a loss of confidentiality but does not grant code execution or other higher-level privileges.
Affected Systems
All Microsoft Edge (Chromium-based) browsers that potentially impacted; no specific version range is listed, so every instance of Edge that has not applied the latest update may be vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 7.4, signifying a high severity issue. The EPSS score is below 1%, indicating that exploitation attempts are expected to be rare. The vulnerability is not listed in CISA’s KEV catalog, so description, it is inferred that an attacker would need to entice a user to open a malicious URL or click a crafted link; once the browser follows that link, it accesses the target file and transmits its data over the network, exposing sensitive information.
OpenCVE Enrichment