Impact
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. The flaw means the browser fails to enforce its intended protection, allowing remote traffic to remove or disable that feature.
Affected Systems
Microsoft Edge (Chromium‑based) browsers installed on Android devices. No specific version is identified, so the vulnerability may affect any recent instance of Edge on Android until a vendor fix is deployed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1 % suggests exploitation is considered unlikely at the time of reporting. The issue is not listed in CISA KEV. Based on the description, the attack vector appears to be remote over a network: a malicious party can send specially crafted traffic to the browser to exploit the improper access control and bypass the protection. Local privilege escalation is not required.
OpenCVE Enrichment