Impact
Improper access control in Microsoft Edge (Chromium‑based) permits an unauthorized attacker to spoof network traffic that the browser interprets as originating from a trusted source. Classified as CWE‑284, the flaw indicates an absence of sufficient authorization checks in the handling of network data. The impact is that users may be led to believe that content comes from a legitimate origin while it has been tampered with, potentially enabling phishing or data injection attacks.
Affected Systems
All installations of Microsoft Edge built on Chromium are potentially vulnerable. The CNA does not limit affected releases, so any current version may be impacted.
Risk and Exploitability
The CVSS v3.1 score of 8.1 signals high severity. The EPSS score of <1% indicates a very low likelihood of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is forging or intercepting network packets that are sent to or from the Edge client; this inference is drawn from the term "spoofing over a network" as the vulnerability falls under missing authorization when processing inbound traffic. Exploitation would require the ability to manipulate network traffic between a user’s machine and the destination of the Edge browser.
OpenCVE Enrichment