Impact
Microsoft Edge (Chromium‑based) contains a server‑side request forgery flaw that enables a client‑side attacker to instruct the browser to send HTTP requests to arbitrary URLs. The vulnerability allows the browser to issue requests that appear to originate from the victim’s system, potentially giving the attacker the ability to probe internal resources or send data to external hosts. This is a typical instance of CWE‑918, where client‑initiated requests are redirected to unintended targets.
Affected Systems
All Microsoft Edge installations that use the Chromium engine are potentially affected, as the CNA vendor/product lists Microsoft Edge (Chromium‑based) without specifying particular builds or patch levels. Administrators should consider every current release of Edge as vulnerable until a patched version is applied.
Risk and Exploitability
The CVSS score of 7.4 classifies the flaw as high severity, while an EPSS score of less than 1 % indicates a low likelihood of widespread exploitation at present. The vulnerability has not yet been listed in the CISA KEV catalog. Attackers would need to deliver malicious or specially crafted web content that causes Edge to perform an unintended request, which is typically achieved by convincing a user to visit a compromised site or by injecting user‑controlled data into a web page. Given the lack of publicly available exploits, the immediate risk remains moderate for environments that reject untrusted web content or tightly control browser usage.
OpenCVE Enrichment