Impact
This vulnerability is a server‑side request forgery (SSRF) in Microsoft Edge (Chromium‑based). An attacker who can supply a malicious URL to the browser can cause Edge to send requests to internal or otherwise restricted network resources, effectively enabling spoofing and potentially allowing the attacker to impersonate trusted services or exfiltrate data. The vulnerability, classified as CWE‑918, could compromise confidentiality and integrity of internal systems if no safeguards are in place.
Affected Systems
Microsoft Edge (Chromium‑based) is affected. No specific edition or version ranges are listed in the available data; all installations of Microsoft Edge (Chromium‑based) should be considered potentially vulnerable until further vendor guidance is released.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. No EPSS score is available, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed. The most likely attack vector is through a malicious web page that the user visits, leveraging the browser to send forged requests. The absence of an official exploit reference further points to a low to moderate exploitation probability under current conditions.
OpenCVE Enrichment