Impact
Missing authorization in Microsoft Edge (Chromium‑based) allows an unauthorized attacker to execute code over a network. The flaw is a direct missing authorization check, classified as CWE‑862. An attacker who can send crafted traffic to the browser can run arbitrary code, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
All builds of Microsoft Edge (Chromium‑based) may be affected, as the published CPE string indicates the entire product family. No specific version ranges are supplied in the advisory, so the attack surface potentially includes all current releases until an update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV. Because the flaw is a missing authorization on a network‑exposed component, the likely attack vector is remote network access by an unauthorized user. The absence of the vulnerability in KEV and the lack of known exploitation data suggest that exploitation may be limited, but the potential for remote code execution warrants prompt mitigation.
OpenCVE Enrichment