Impact
A type‑confusion flaw (CWE‑843) in Microsoft Edge’s Chromium engine allows an attacker to trigger an incompatible type access during resource handling. If an unauthorized party can influence Edge to load data that is interpreted as a different type, the runtime may execute arbitrary code, resulting in remote code execution on the user computer.
Affected Systems
All builds of Microsoft Edge that use the Chromium engine are vulnerable. The advisory does not specify exact version numbers, so every current or legacy Chromium‑based Edge installation is potentially affected until a patch is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 9.0, marking it as critical. The EPSS score is less than 1 %, indicating a low probability of exploitation at present, and it is not listed in CISA’s KEV catalog. Based on the description, the typical attack scenario would involve a remote network actor who can supply malicious content to the browser, for example via crafted URLs or manipulated network responses. An update addressing the flaw is recommended when it becomes available.
OpenCVE Enrichment