Impact
The vulnerability is a type‑confusion bug that allows an attacker to cause the browser to access a resource using an incompatible type. This flaw can lead to arbitrary code execution within the context of Microsoft Edge (Chromium‑based). The flaw is exploitable by an unauthorized attacker to run code on a system that opens the browser, potentially compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
The affected product is Microsoft Edge (Chromium‑based) as published by Microsoft. No specific version range is listed, so all installed instances of Microsoft Edge that use the Chromium engine are potentially vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, and the vulnerability is exploitable over the network by an unauthenticated attacker. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote network exploit that does not require user interaction beyond visiting malicious content. The exploit would trigger the type confusion and result in arbitrary code execution inside the browser process.
OpenCVE Enrichment