Impact
The vulnerability is a type confusion flaw that allows an attacker with network access to craft a malicious resource that, when processed by Microsoft Edge (Chromium-based), results in arbitrary code execution. This flaw exposes users to complete compromise of their local environment, permitting the attacker to read, modify or delete data, install malware, or gain persistence. The weakness is identified as CWE‑843: Type Confusion.
Affected Systems
The flaw affects Microsoft Edge (Chromium-based) across all current installations where the vulnerable code path has not been patched. No specific version ranges are provided, so all iterations that contain the unpatched code are susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the near term, especially since the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the attack vector would be remote, typically via a malicious web page or crafted content that sends a specially formatted payload to the browser. Because the flaw involves a type confusion, it likely requires the attacker to embed a specially formatted payload; thus, the exploitation prerequisites include network connectivity to the targeted client and a user interacting with the malicious content. The combination of moderate severity and low exploitation probability means that while the damage could be complete if exploited, the risk of an attack in the current landscape is relatively low.
OpenCVE Enrichment