Impact
The flaw is a use‑after‑free vulnerability in Microsoft Edge’s Chromium engine that lets an attacker trigger memory corruption from crafted network traffic. This can lead to arbitrary code execution running with the privileges of the Edge process, exposing the confidentiality, integrity, and availability of the device. The flaw is identified as CWE‑416.
Affected Systems
Microsoft Edge (Chromium‑based) is the affected product. No specific version range is listed, meaning any installation that has not applied the latest security update could be at risk.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be over a network connection that the browser can receive, so even without local credentials an attacker can send malicious traffic to provoke the use‑after‑free and achieve remote code execution.
OpenCVE Enrichment