Impact
The vulnerability permits an attacker to externally control the file name or path used by Microsoft Edge (Chromium-based). Because this input is not sanitized, an adversary can cause Edge to resolve and process a malicious path, resulting in the execution of arbitrary code on the user’s system and compromising confidentiality, integrity, and availability. The weakness is identified as CWE‑73, which describes untrusted input influencing file system paths.
Affected Systems
Microsoft Edge (Chromium-based) – the CVE does not list a specific affected version, implying that all current releases of Edge may be vulnerable until an official update is issued.
Risk and Exploitability
The CVSS score of 8.1 reflects a high severity vulnerability. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over a network, such as a malicious web page or a crafted link that causes Edge to process a crafted file name or path. No additional prerequisites or conditions are detailed in the CVE data.
OpenCVE Enrichment