Impact
The flaw arises from improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium‑based). An attacker who can influence how the browser parses an input can cause the application to execute arbitrary code, thereby gaining full control of the victim’s system. The vulnerability is specifically related to how certain URL or request components are handled, allowing code execution over a network.
Affected Systems
The affected product is Microsoft Edge (Chromium‑based). No specific version range is provided in the advisory, so all releases prior to the latest update may contain the flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact. The EPSS score is not available, and the vulnerability has not been listed in the CISA KEV catalog. Attackers could exploit this over a network connection by delivering crafted inputs to the browser. While the lack of an EPSS score and KEV status reduces immediate public exploitation pressure, monitored risk remains, especially for systems exposed to untrusted traffic.
OpenCVE Enrichment