Impact
Improper control of code generation in Microsoft Edge (Chromium-based) allows an attacker to inject and execute crafted code, leading to spoofing of network traffic. The vulnerability falls under CWE-94 and can enable an unauthorized actor to impersonate legitimate communications, potentially affecting confidentiality and integrity of data exchanged over the network.
Affected Systems
Microsoft Edge (Chromium-based) is the only vendor/product listed, with no specific version information provided in the advisory.
Risk and Exploitability
The CVSS score is 6.1, indicating a medium-impact vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker who can deliver malicious input to the vulnerable component over a network. No specific restrictions on the attacker’s privileges are mentioned, suggesting the exploit could be performed from an external network context if the affected code path is reachable.
OpenCVE Enrichment