Impact
The flaw is an improper authorization weakness, classified as CWE‑285, located in Microsoft Edge’s Chromium engine. It enables an attacker to cause the browser to run arbitrary code, which operates with the same privileges that the Edge process itself holds. This can compromise the confidentiality, integrity, and availability of the system on which Edge is running.
Affected Systems
All installations of Microsoft Edge that use the Chromium engine are potentially affected. The CVE entry does not list specific product versions; consult the Microsoft security advisory for exact version details.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3, indicating high severity, and an EPSS score of less than 1% suggesting a very low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. The description notes that an attacker can trigger code execution over a network, and based on this information it is inferred that the attacker does not need local system access and can target any machine running Edge from an accessible network connection.
OpenCVE Enrichment