Impact
Microsoft Edge (Chromium‑based) contains an improper neutralization of input during web page generation that can produce a cross‑site scripting flaw. An attacker who successfully delivers crafted user data in the context of a valid user session. This injected code can masquerade as the authenticated user or perform operations on their behalf, effectively enabling spoofing. The flaw is classified as CWE‑79 and, based on the description, it appears to be confined to the browser context; there is no indication of capabilities beyond this scope.
Affected Systems
Microsoft Edge (Chromium‑based) are affected. The advisory does not supply specific version numbers, so any installation that has not yet applied the most recent Microsoft Edge update may be vulnerable. To determine exact risk, review the latest Microsoft update release notes for the product.
Risk and Exploitability
The CVSS score of 7.2 indicates a significant impact while the EPSS of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a malicious web page that a victim loads or a compromised site that serves the exploit; the attacker must have the user navigate to the crafted page. Once the script runs, it can subvert trust and masquerade as the user, though it does not provide enabling remote code execution outside the browser.
OpenCVE Enrichment