Impact
Microsoft Edge (Chromium-based) contains a heap-based buffer overflow that allows an unauthorized attacker to execute arbitrary code on a target system. When the browser parses malformed network data, the overflow can be triggered without user interaction, enabling the attacker to inject and run malicious code within the browser process. This flaw grants full access to the system, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability impacts Microsoft Edge (Chromium-based) distributed by Microsoft. No version range is specified in the advisory, so all current releases of the Chromium‑based Edge browser are potentially affected until a patch is installed.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score of less than 1% indicates that, although the attack is theoretically possible, real‑world exploitation is currently unlikely but still feasible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over the network, most likely through a malicious web page or content that the browser processes, requiring no special privileges or user interaction beyond normal browsing activity.
OpenCVE Enrichment