Impact
The vulnerability is an improper authorization flaw, classified as CWE-285, in Microsoft Edge's Chromium engine. An attacker who can craft malicious network traffic can compel the browser to run arbitrary code. This gives the attacker the ability to execute code on the machine with whatever privileges the Edge process runs under.
Affected Systems
All installations of Microsoft Edge that use the Chromium engine are potentially vulnerable. The CVE data does not specify which exact versions are affected; consult the Microsoft security advisory for detailed version information.
Risk and Exploitability
With a CVSS score of 8.3 the flaw is high severity, and the EPSS score of less than 1% indicates a very low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. A remote attacker with network access to a device running Edge can exploit this flaw through crafted network traffic.
OpenCVE Enrichment