Impact
A use‑after‑release flaw in Microsoft Edge (Chromium-based) classified as CWE‑672 allows an attacker to read data that should no longer be accessible after the resource has been released. The vulnerability can result in information disclosure over a network, potentially exposing sensitive or confidential material the user did not intend to share.
Affected Systems
Microsoft Edge (Chromium-based) is the affected product. No specific version ranges are provided in the advisory, so all currently supported releases are potentially vulnerable until Microsoft releases a patched build.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Information may be disclosed over a network; the likely attack vector involves delivering malicious content or otherwise triggering the use‑after‑release condition in a running Edge instance, which could require user interaction or remote content delivery, although the exact path is not detailed.
OpenCVE Enrichment