Impact
Microsoft Edge (Chromium‑based) contains a server‑side request forgery flaw that permits an unauthorized attacker to perform spoofing over a network, as stated in the advisory. This issue is identified as CWE‑918 and enables the attacker to craft requests that the browser will forward to arbitrary network addresses, thereby manipulating internal traffic for spoofing purposes.
Affected Systems
The vulnerability affects Microsoft Edge (Chromium‑based). No specific version information is supplied, so all current and legacy builds may be impacted until a patch is applied.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The advisory does not explicitly state the attack vector, so the only confirmed detail is the existence of SSRF that permits network spoofing.
OpenCVE Enrichment