Impact
Improper input validation in Microsoft Edge for Android enables an unauthorized attacker to tamper with content delivered over a network. The flaw allows modification of data before the browser renders it, compromising the integrity of the received information.
Affected Systems
Microsoft Edge for Android (Chromium‑based) on Android devices is affected. Any device running the current default build of the browser that has not yet applied the latest update is vulnerable; the advisory does not list specific versions, so the entire breadth of unpatched builds is impacted.
Risk and Exploitability
The CVSS score of 5.4 denotes moderate severity. An EPSS score below 1% indicates a low probability of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and no publicly available exploit is known. The likely attack vector is remote over a network connection, as the flaw is accessed through standard web traffic. If successful, the attacker can manipulate the data that the browser receives, potentially affecting data integrity for the user.
OpenCVE Enrichment