Impact
Microsoft Edge (Chromium‑based) contains a server‑side request forgery flaw (CWE‑918) that enables an attacker to instruct the browser to send HTTP requests to arbitrary internal or external network addresses. By leveraging this ability, a malicious web page or script could cause Edge to reach services that are normally unreachable, effectively spoofing traffic and potentially bypassing isolation boundaries. This flaw permits the attacker to manipulate internal network communications, but does not provide direct code execution or privilege escalation. The impact is that confidential data or internal services could be accessed or manipulated through the spoofed requests.
Affected Systems
The vulnerability affects Microsoft Edge (Chromium‑based) for all platforms. No specific version numbers are supplied in the advisory, so any current or legacy build of Edge may be vulnerable until the official patch is installed.
Risk and Exploitability
The CVSS base score of 5.4 places the flaw in the medium severity range. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector inferred from the nature of SSRF is that an attacker must host a malicious page or payload that is opened in Edge, prompting the browser to make calls to arbitrary network addresses. While the attack requires the user to load such content, the potential to manipulate internal traffic makes it a concern for environments with sensitive internal services. Overall, the risk is moderate but mitigable through patching.
OpenCVE Enrichment