Impact
Microsoft Edge (Chromium-based) contains a use‑after‑free vulnerability that allows an authorized attacker to execute arbitrary code remotely. The flaw can be triggered when the browser processes certain network artifacts, leading to full code execution in the user's context. This weakness aligns with CWE‑416.
Affected Systems
The vulnerability affects Microsoft Edge (Chromium-based) on Windows, Android, iOS, Linux, and macOS. Product versions are not explicitly listed in the advisory, so all currently deployed releases are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting it is not a widely exploited or actively targeted flaw at this time. However, the presence of a use‑after‑free that enables remote code execution means the exploit could have devastating consequences if an attacker achieves the necessary authorized network access. The attack vector is likely remote, via malicious web content or network requests sent to the browser.
OpenCVE Enrichment