Impact
The vulnerability is a heap-based buffer overflow in Microsoft Edge (Chromium-based) that allows an unauthorized attacker to execute arbitrary code over a network. This flaw stems from improper memory handling during processing of web content, classified as CWE-122, and can lead to full compromise of the affected system if the attacker succeeds.
Affected Systems
The affected vendor is Microsoft, specifically the Edge browser built on the Chromium engine. No specific version range is listed in the advisory, so all installations of the Chromium‑based Edge that are not updated to the latest release may be vulnerable.
Risk and Exploitability
The assessment shows a CVSS score of 8.3, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered over a network and an attacker does not need local privileges, the likelihood of exploitation is significant for systems exposed to the Internet.
OpenCVE Enrichment