Impact
A use‑after‑free flaw (CWE‑416) in Microsoft Edge (Chromium‑based) allows memory corruption that can be leveraged by an attacker to execute arbitrary code. This vulnerability is triggered by loading a specially crafted web resource, and it can lead to full system compromise, data theft, or service disruption for the user whose browser is affected.
Affected Systems
Microsoft Edge (Chromium‑based) is the affected product. The Microsoft Security Response Center provides version ranges that require the update; specific CVE‑affected releases are listed only in the advisory, and all supported Chromium‑based Edge builds are susceptible.
Risk and Exploitability
The CVSS score of 8.3 classifies the flaw as High severity. The EPSS score of less than 1% indicates a low, but non-zero, probability of exploitation. The vulnerability is listed as not in the CISA KEV catalog. It is inferred that the exploit requires a remote network attacker able to deliver a malicious page or resource to the victim's Edge instance; given the low exploitation probability, immediate mitigation is still warranted to prevent potential high‑impact attacks.
OpenCVE Enrichment