Impact
Microsoft describes an origin validation error in its Chromium-based Edge browser that allows an unauthorized attacker to perform spoofing over a network. That error can cause the browser to accept a forged or manipulated origin header, enabling the creation of a fake site that appears legitimate to the user. The resulting impact is that an attacker could trick a user into interacting with a malicious site that looks authentic, potentially leading to credential theft or other credential-based attacks.
Affected Systems
The affected product is Microsoft Edge built on Chromium, as distributed by Microsoft. No specific version range is listed, so all currently supported releases of Edge that contain the unpatched code are likely vulnerable. Users should verify the version against Microsoft’s update guide and only rely on the advisory for exact version ranges.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. The vulnerability is listed as not in the CISA KEV catalog, and no EPSS score is available. The likely attack vector is a malicious website or network traffic that a user visits; the attacker must be able to influence the browsing context. If exploited, the attacker could spoof a legitimate domain, potentially causing the user to divulge sensitive information. The risk is therefore significant, especially if the user has administrative access to corporate resources. Mitigation depends on applying the patch before a malicious user can exploit the flaw.
OpenCVE Enrichment