Impact
A time‑of‑check to time‑of‑use (toctou) race condition in Microsoft Edge for Android allows an attacker to inject and execute code without user interaction. The flaw permits abuse of a network‑initiated race, letting an attacker bypass intended browser checks and run arbitrary code within the Edge process, potentially compromising the entire device.
Affected Systems
Microsoft Edge (Chromium‑based) for Android is affected. No specific version numbers are listed in the advisory, so any installation that has not incorporated the latest Microsoft Edge update is presumed vulnerable. The vulnerability is limited to the Android platform and does not affect other browsers or operating systems.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, while the EPSS score of <1% indicates a low probability of exploitation at present. The issue is not listed in CISA’s KEV catalog, meaning no public exploit has been observed. The description and CWE‑367 suggest that a remote attacker can trigger the race condition using crafted network traffic directed at Edge without requiring the user to open a malicious link or provide input.
OpenCVE Enrichment