Impact
Microsoft Edge (Chromium-based) contains an insufficient UI warning for dangerous operations that allows an unauthorized attacker to deliver spoofed content over a network. The flaw permits the browser to present deceptive pages without alerting the user, enabling an attacker to trick the user into interacting with malicious content. The weakness is classified as CWE‑357, which identifies spoofing behaviors rather than information disclosure.
Affected Systems
The affected product is Microsoft Edge (Chromium-based). No version details are provided, so all current installations may be vulnerable until the official fix is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates a low overall severity, and the EPSS score of < 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The likely attack vector is over a network where an attacker can host or redirect content that bypasses the browser’s warning dialogs; exploitation requires the user to interact with the spoofed page, as the flaw is only in the UI warning mechanism.
OpenCVE Enrichment