Impact
The vulnerability is an origin validation error in Microsoft Edge (Chromium-based) that permits an unauthorized attacker to tamper with data served to the browser. This weakness could allow the modification of content or the injection of malicious data, potentially leading to data integrity violations.
Affected Systems
Affected systems are all versions of Microsoft Edge (Chromium-based) on supported platforms (Windows, macOS, Linux, etc.) for which Microsoft has not yet released a fix. No specific version range is provided in the CNA data.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based, requiring the attacker to deliver a malicious origin to the victim browser. Until the vendor releases a patch, the risk persists and should be monitored.
OpenCVE Enrichment