Impact
Improper input validation in Microsoft Edge (Chromium‑based) allows an attacker to send crafted data that causes the browser to execute arbitrary code. This flaw, categorized as CWE‑20, can lead to loss of confidentiality, integrity, and availability of the host system when exploited.
Affected Systems
Microsoft Edge (Chromium‑based) is affected. No specific version numbers are disclosed; all current releases should be treated as potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests exploitation is unlikely in the short term. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been reported. Based on the description, the likely attack vector is a remote network injection that delivers malicious input to the browser process, allowing code execution with the privileges of the running instance.
OpenCVE Enrichment