Impact
Improper access control in Microsoft Edge (Chromium‑based) enables an unauthorized attacker to perform spoofing over a network. The vulnerability is classified as CWE-284, indicating insufficient authorization checks that may allow an attacker to impersonate another context. While the description does not detail specific packet manipulation, it is inferred that the attacker could craft packets that the browser accepts as originating from a trusted source, potentially leading to the user being misled about the provenance of web content.
Affected Systems
All installations of Microsoft Edge built on Chromium are potentially affected. The CNA list does not specify a narrow version range, so any release of the Chromium‑based Edge might be vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.1 classifies the flaw as high severity. The EPSS score is reported as <1%, indicating a very low probability of exploitation at present. The flaw is not yet listed in CISA’s KEV catalog. Because the vulnerability relies on network spoofing, an attacker who can intercept or forge traffic between the Edge client and the network could exploit it, unless mitigated by proper network controls and the official patch.
OpenCVE Enrichment