Impact
This flaw is a type confusion vulnerability (CWE‑843) that enables an attacker to use a resource with an incompatible type in Microsoft Edge (Chromium-based), allowing the execution of arbitrary code on the affected system. The vulnerability is exploitable over a network, meaning that a malicious actor can trigger it by delivering crafted web content or malicious attachments to a user’s browser. Successful exploitation results in loss of confidentiality, integrity, and availability since the code runs with the privileges of the Microsoft Edge (Chromium-based) is the affected product. No specific fixed version is listed in the advisory, so all currently installed versions that have.
Affected Systems
Microsoft Edge (Chromium-based) versions that have not yet received the latest security update from Microsoft. All Chromium-based build and have not been patched are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description would allow the attacker to run arbitrary code with the privileges of the Edge process.
OpenCVE Enrichment