Impact
The vulnerability is a buffer over‑read in Microsoft Edge (Chromium‑based) that can allow an authorized attacker to execute code remotely. The weakness corresponds to CWE‑126, which describes situations where insufficient bounds checking can lead to memory corruption or code execution. If exploited, the attacker could run arbitrary code in the context of the application, potentially gaining control over the local system, accessing confidential information, or further propagating malware.
Affected Systems
Microsoft Edge (Chromium‑based) is listed as the affected product. Specific version information is not provided in the available data, so all released builds of Edge could be vulnerable until a fixed update is issued.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity for the vulnerability, and the EPSS score is not available, suggesting limited data on current exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be a network‑based interaction that requires an authorized attacker, as the description states the attacker must be able to interact over a network. Given the medium score and the lack of known active exploitation, the risk is moderate but still warrants prompt attention.
OpenCVE Enrichment