Impact
Microsoft Edge (Chromium‑based) contains an improper access control flaw (CWE‑284) that permits an unauthorized attacker to bypass a security feature that is enforced over a network connection. The flaw enables the attacker to perform actions normally protected by that feature, though the advisory does not enumerate the specific capabilities. Because the bypass undermines Edge’s security mechanism, the potential impact includes unauthorized execution of privileged actions or data access within the browser context.
Affected Systems
The vulnerability affects Microsoft Edge (Chromium‑based). No version constraints are listed in the advisory, so all installed instances of the Chromium‑based Edge browser are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.2 classifies the flaw as high severity; its EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog, suggesting no known large‑scale exploitation. Based on the description, the likely attack vector is remote over a network where an attacker can send crafted traffic to trigger the access‑control bypass. No public exploit is documented beyond routine network communication to the browser.
OpenCVE Enrichment