Impact
This vulnerability is a type confusion flaw (CWE‑843) in Microsoft Edge (Chromium‑based). It allows an attacker who can deliver a specially crafted resource over the network to instruct the browser to access the resource using an incompatible type, thereby bypassing a built‑in security feature. The description does not state that secrets are exposed or that privilege escalation is possible; however, the bypass could potentially enable additional attacks that rely on the compromised protection.
Affected Systems
All releases of Microsoft Edge (Chromium‑based) are potentially impacted, as the CVE data does not provide version exclusions. Until a fixed version is installed, any deployment of the browser may be vulnerable.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in CISA’s KEV catalog. The stated attack vector is a network-based delivery of malicious content; the attacker must successfully make the victim’s Edge browser process an incompatible resource in order to bypass the security feature.
OpenCVE Enrichment