Impact
An attacker can externally control a file name or path that Microsoft Edge (Chromium-based) interprets, enabling the attacker to spoof network resources. The vulnerability is a form of path traversal (CWE‑73) that lets an unauthorized actor pose as legitimate files or services, potentially deceiving users or intercepting traffic.
Affected Systems
All installed Microsoft Edge browsers based on the Chromium engine are potentially affected. No specific version range is listed, so any current release of Microsoft Edge (Chromium-based) should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium risk. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likelihood of exploitation depends on an attacker being able to supply a crafted file path that the browser processes; this could occur via malicious links or scripts that open Edge with such a path. While the attack vector is inferred to be remote, the lack of public exploit data suggests limited current exploitation risk, but the medium severity warrants prompt mitigation.
OpenCVE Enrichment