Impact
A use‑after‑free bug in the Chromium rendering engine of Microsoft Edge allows an unauthorized attacker to execute code over a network. The flaw, which is classified as CWE‑416, can let an attacker run arbitrary code with the privileges of the Edge process and potentially compromise the user’s data or the broader system.
Affected Systems
Microsoft Edge (Chromium‑based) is affected. No specific version range is supplied; the vulnerability applies to the product until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is not available, but the attack vector is remote, relying on network traffic that can trigger the use‑after‑free in the browser. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no known large‑scale exploitation, yet the potential for remote code execution remains substantial.
OpenCVE Enrichment