Impact
Microsoft Edge (Chromium-based) suffers from improper link resolution before file access "link following" that permits an unauthorized attacker to read the contents of local or network files and transmit that data over a network. The flaw is a CWE‑59 Path Traversal issue, leading to a loss of confidentiality only; it does not provide code execution or higher‑level privileges.
Affected Systems
All versions of Microsoft Edge (Chromium‑based) that have not applied the latest security update are potentially vulnerable. No specific version range is given, so any installed Edge that is not up‑to‑date may be affected.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity issue. The EPSS score is below 1%, suggesting that exploitation attempts are expected to be rare, and the vulnerability is not listed in CISA’s KEV catalog. The likely exploitation flow involves an attacker enticing a user to open a crafted link or visit a malicious webpage; once the browser follows that link, it can access the target file and send its contents back to the attacker, thereby exposing sensitive information.
OpenCVE Enrichment