Impact
Microsoft Edge (Chromium-based) contains a type‑confusion flaw (CWE‑843) that allows an attacker to cause the browser to interpret a network resource as a different type. When this occurs the browser treats the resource as if it came from a trusted source, enabling the attacker to spoof the source of that resource over a network and potentially impersonate legitimate servers or clients.
Affected Systems
Microsoft Edge (Chromium-based). No specific version information is provided in the advisory, so the exact scope of affected releases cannot be determined from the available data.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1 % suggests that exploitation is unlikely at present. The flaw can be abused via a network‑based attack in which an attacker sends crafted responses that trigger type confusion in the victim’s browser. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment