Impact
The vulnerability is a missing authorization check in Microsoft Edge (Chromium-based) that permits an unauthorized local attacker to tamper with the browser or its configuration. The flaw is a classic permissions bypass (CWE-862) that allows modification of local data or settings without proper validation. Such tampering could facilitate persistence of malware, logging of browsing activity, or compromise of local user credentials stored by Edge.
Affected Systems
All versions of Microsoft Edge (Chromium-based) are potentially affected, as no specific version constraints are listed. The vulnerability impacts users running the Chromium‑based Edge browser on Windows systems, regardless of the installed build number or update channel.
Risk and Exploitability
With a CVSS score of 6.2, the vulnerability is considered moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, indicating no publicly known exploits as of this analysis. The likely attack vector is local execution: an attacker must have local access or the ability to run code on the target machine. Once the missing authorization is leveraged, tampering can be performed without elevated rights, though the attacker would still require a user context on the machine.
OpenCVE Enrichment