Impact
Microsoft Edge (Chromium‑based) contains a server‑side request forgery flaw that enables a client‑side attacker to instruct the browser to send HTTP requests to arbitrary URLs. The vulnerability allows the browser to issue requests that appear to originate from the victim’s system, potentially giving the attacker the ability to probe internal resources or send data to external hosts. This is a typical instance of CWE‑918, where client‑initiated requests are redirected to unintended targets.
Affected Systems
All Microsoft Edge installations that use the Chromium engine are potentially affected, as the CNA vendor/product lists Microsoft Edge (Chromium‑based) without specifying particular builds or patch levels. Administrators should consider every current release of Edge as vulnerable until a patched version is applied.
Risk and Exploitability
Based on the description, the likely attack vector is the delivery of malicious or specially crafted web content that causes Edge to perform an unintended request. The attacker can lure a user to visit a compromised site or inject user‑controlled data into a page. The CVSS score of 7.4 indicates high severity, but the EPSS score of less than 1 % suggests a low chance of widespread exploitation at present, and the vulnerability is not yet listed in CISA KEV. If exploited, the attacker can pose as the victim’s system to query internal resources or send data to external hosts, enabling internal reconnaissance or data exfiltration.
OpenCVE Enrichment