Impact
Microsoft Edge (Chromium-based) contains an origin validation error that allows an unauthorized user to tamper locally with the browser or its underlying data. This flaw enables modification of local resources or potentially the execution of unintended code, which could lead to data compromise or privilege escalation. The vulnerability aligns with CWE-346: Incorrect Privilege Management.
Affected Systems
All versions of Microsoft Edge (Chromium-based) are affected; specific version ranges are not disclosed in the advisory.
Risk and Exploitability
The CVSS score is 6.8, indicating a moderate to high risk. Exploitation likelihood is unclear due to the absence of an EPSS score, and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. The attack vector is inferred to be local, meaning an attacker would need unauthenticated local access to the affected machine. Overall, the risk is significant for environments where Edge is permitted to run untrusted content.
OpenCVE Enrichment