Impact
The flaw is a use‑after‑free bug that allows an attacker who can reach the browser over a network to execute arbitrary code. The impact is the compromise of confidentiality and integrity of the victim machine. The weakness is classified as CWE-416.
Affected Systems
Microsoft Edge (Chromium‑based) from Microsoft is affected. Version information is not supplied in the data, so any installation of Edge the relevant update after the disclosure date could be at risk.
Risk and Exploitability
The CVSS score of 8.3, a high severity, while the EPSS score of < 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread attacks yet. The likely attack vector is remote over a network, as the description specifies that code execution is possible from a remote endpoint.
OpenCVE Enrichment