Impact
The vulnerability stems from improper neutralization of input used for LLM prompting in Microsoft Edge for iOS. An attacker can supply crafted input that is passed to the language model component without adequate sanitization, allowing the attacker to spoof identity or source information over a network request. This can lead to the appearance of legitimate traffic originating from the browser when in fact it is controlled by an attacker.
Affected Systems
Microsoft Edge (Chromium-based) and Microsoft Edge for iOS are affected. No specific version numbers are listed, so all current releases of the iOS app are considered vulnerable until the official patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate complexity and impact; the EPSS score of 0.00298 indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation does not require elevated privileges and can be carried out remotely over the network by an attacker who can influence the LLM prompting mechanism. The likely attack vector involves a remote attacker sending crafted prompts to the browser’s LLM subsystem to generate spoofed network traffic or requests.
OpenCVE Enrichment