Impact
This vulnerability arises from improper deserialization of untrusted data within Microsoft Edge (Chromium-based). The flaw permits an attacker to execute arbitrary code, leading to full system compromise. The weakness is classified as CWE‑502, indicating insecure handling of serialized objects. The impact is therefore the loss of confidentiality, integrity, and availability for any affected system that runs the vulnerable browser.
Affected Systems
The affected product is Microsoft Edge (Chromium-based). No specific version information is listed in the CNA data, so any installation of the Chromium‑based Edge that remains unpatched is potentially vulnerable.
Risk and Exploitability
The CVSS score is 8.3, placing this vulnerability in the high severity range. The EPSS score is less than 1%, suggesting that the likelihood of exploitation is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog, indicating no known weaponized exploitation in the wild at the time of this analysis. The likely attack vector is remote, via network access to the victim’s machine that hosts Edge; an unauthorized attacker could feed a crafted serialized payload to the browser to trigger execution.
OpenCVE Enrichment