Impact
Improper input validation in Microsoft Edge (Chromium‑based) permits an attacker to deliver specially crafted data that causes the browser to execute arbitrary code. This flaw, classified as CWE‑20, can compromise the confidentiality, integrity, and availability of the host system when exploited, potentially allowing remote execution of malware or scripts under the privileges of the browser process.
Affected Systems
Microsoft Edge (Chromium‑based) is affected. No specific version numbers are disclosed; all current releases should be considered potentially vulnerable until a patch is installed.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog, implying no documented widespread exploitation. Based on the description, the likely attack vector is a remote network delivery of malicious input that triggers the browser to execute code with the privileges of the running instance.
OpenCVE Enrichment