Impact
A heap-based buffer overflow exists in Microsoft Edge (Chromium-based), enabling an unauthorized attacker to execute arbitrary code. The flaw is triggered by malformed data processed over the network, allowing malicious code injection into the browser process and leading to complete compromise of the affected system's confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Microsoft Edge (Chromium-based) as distributed by Microsoft. No specific version range is detailed in the advisory, implying that all current releases of the Chromium-based Edge browser are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as High severity. The EPSS indicator of less than 1% suggests that real-world exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over the network, most likely via a malicious or compromised web page or exploited content reaching the browser’s parsing routines. Given the absence of, yet the potential impact justifies prioritizing remediation.
OpenCVE Enrichment