Impact
The flaw arises from an incorrect authorization check in Microsoft Edge (Chromium-based). The vulnerability permits an unauthorized attacker to disclose information over a network. The weakness is classified as CWE‑863, indicating an authorization bypass. Because the description does not specify the exact type or scope of data that can be disclosed, the potential impact may range widely, but it remains an information disclosure flaw.
Affected Systems
The vulnerable component is Microsoft Edge (Chromium-based). No specific version information is provided, so all supported Windows installations of Edge that have not yet received the Microsoft patch may be affected. All users running Edge are therefore at risk until the update is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity. The EPSS score is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability description states that exploitation occurs over a network, but it does not detail additional prerequisites, meaning that an attacker would need a way to invoke the affected functionality from outside the local machine to trigger the disclosure.
OpenCVE Enrichment