Impact
This vulnerability originates from an origin validation error that allows an unauthorized attacker to spoof source identities over a network. The flaw is categorized as CWE‑346, a weakness that undermines authenticity by permitting an attacker to forge an origin header, potentially leading to deceptive communications or impersonation of legitimate services.
Affected Systems
Microsoft Edge (Chromium‑based) is affected. No specific version information is provided, so all current releases of this browser could be impacted until a fix is released.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk, and the EPSS score is not available, making it unclear how frequently the vulnerability is actively exploited. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would require an attacker to send crafted network traffic that bypasses the browser’s origin validation, enabling spoofed content or connections to appear as legitimate sources.
OpenCVE Enrichment