Impact
Improper neutralization of input during web page generation in Microsoft Edge (Chromium‑based) creates a cross‑site scripting flaw (CWE‑79). An attacker who delivers crafted web content can cause the browser to render malicious input, allowing the attacker to manipulate UI elements, prompts, or messages to deceive users into believing they are interacting with legitimate interfaces. This can lead to the disclosure of sensitive information or the execution of unintended actions.
Affected Systems
Microsoft Edge (Chromium‑based) is potentially impacted; no specific versions are disclosed, so any current unpatched release could be vulnerable. The advisory links Microsoft’s update guide for available patches.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity. The EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the delivery of malicious or compromised web content over a network to the browser, requiring the user to load a page containing the crafted input before the exploit is successful.
OpenCVE Enrichment