Impact
A flaw in origin validation within Microsoft Edge (Chromium‑based) allows an unauthorized attacker to disclose sensitive information over a network. The vulnerability lies in how the browser verifies the origin of requests, enabling the attacker to retrieve data that should be restricted to a specific origin. The impact is pure information disclosure, with no direct compromise or execution capabilities indicated.
Affected Systems
Microsoft Edge (Chromium‑based) is the affected product. No specific affected versions are listed in the data, so all installations of this browser could be vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 8.1 signals a high‑severity issue. Because an EPSS score is not available, the current probability of exploitation in the wild is unknown, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly documented exploits. The attack vector is inferred to be remote, leveraging crafted network traffic that bypasses the browser’s origin checks to exfiltrate data. Given the high severity and lack of other mitigations, remedial action is required urgently.
OpenCVE Enrichment