Impact
Use after free vulnerability in Microsoft Edge (Chromium‑based) permits an unauthorized attacker to execute code over the network. Triggered by malicious web content, the flaw arises from improper memory deallocation, allowing the attacker to run arbitrary code within the browser process. The primary consequence is remote code execution, potentially compromising the confidentiality, integrity, and availability of the user’s data and the underlying operating system if escalation occurs.
Affected Systems
Microsoft Edge (Chromium‑based) is the affected product. The data does not specify particular version ranges; no release information is provided. Administrators should verify the installed Edge version and consult Microsoft for any applicable security updates.
Risk and Exploitability
CVSS base score of 4.3 indicates low severity. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The probable attack vector is a network‑based exploitation triggered by loading malicious content in Edge. Success requires the victim to visit a compromised page, so the risk is confined to exposed users. Nevertheless, because the issue can lead to remote code execution, it is prudent to monitor for related attacks and apply patches when available.
OpenCVE Enrichment