Impact
The flaw is an improper access control in Microsoft Edge’s Chromium core that enables an attacker to spoof network identities. This can allow a malicious host to masquerade as a legitimate server and redirect or inject traffic into a browser session, undermining the authenticity of network communications. The vulnerability does not grant arbitrary code execution or system compromise but does expose users to phishing or man‑in‑the‑middle attacks.
Affected Systems
Microsoft Edge (Chromium-based) browsers are affected. No specific release numbers are listed, so all current public releases remain vulnerable until an official Microsoft update is applied.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity issue, while the EPSS score of <1% reflects a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based; an untrusted party could send a crafted page or manipulate traffic between the browser and remote servers to trigger the spoofing behavior.
OpenCVE Enrichment