Impact
This vulnerability is a type‑confusion flaw in Microsoft Edge (Chromium‑based). The browser incorrectly treats an object as a different type than intended, allowing an attacker who can deliver malicious content over a network to execute arbitrary code on the user’s device. The issue is classified as CWE‑843 and provides remote code execution capabilities that can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Any installation of Microsoft Edge (Chromium‑based) on supported platforms is potentially vulnerable until a vendor update is applied. The CVE entry does not specify a affected release number, so all current releases of Edge that have not been patched are at risk. This includes Windows, macOS, and Linux builds.
Risk and Exploitability
The assigned CVSS score of 8.3 marks the vulnerability as high severity, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. Edge is not listed in CISA’s KEV catalog, meaning no confirmed exploits are known yet. Based on the description, the likely attack vector requires an attacker to deliver malicious web content to a user, exploiting the type‑confusion flaw to trigger remote code execution. If successful, the attacker could gain full control over the victim’s system.
OpenCVE Enrichment