Impact
An untrusted pointer dereference flaw in Microsoft Edge (Chromium-based) allows an unauthenticated attacker to elevate privileges over a network. The weakness, classified as CWE-822, involves dereferencing a pointer that references data that has not been properly verified. Exploiting this flaw can allow an attacker to gain higher-level access on a target system, compromising confidentiality, integrity, and availability. Because specific version information is not provided, we infer that any Edge installation lacking the official patch is potentially vulnerable.
Affected Systems
Microsoft Edge (Chromium-based). All supported Edge releases published before the issuance of the patch are potentially vulnerable until the update is applied. No specific version numbers are listed. We infer that every unpatched Edge release falls within the affected scope due to the absence of version constraints.
Risk and Exploitability
The CVSS score of 8.3 signals high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploitation. An attacker must cause Edge to dereference an untrusted pointer. Attack prerequisites include an unpatched Edge installation and sufficient network access. Because the impact is not limited to a narrow version range, we infer that the vulnerability could affect all unpatched installations. If exploited, the attacker could elevate privileges on the host system, potentially gaining full control.
OpenCVE Enrichment