Impact
Microsoft Edge (Chromium-based) contains a type confusion flaw that allows an attacker to access resources using an incompatible type. This vulnerability, classified as CWE‑843, enables the attacker to execute arbitrary code across the network. The flaw occurs when Edge processes an unexpected resource, leading to control flow hijacking and remote code execution without user interaction.
Affected Systems
The affected product is Microsoft Edge (Chromium-based). No specific version numbers are provided in the current data, so all supported builds of the Chromium‑based Edge browser are potentially vulnerable until updated.
Risk and Exploitability
The CVSS score of 8.8 places this issue in the high‑severity range. The EPSS value is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no confirmed production exploitation at this time. Nevertheless, the attack vector is inferred to be network‑based, as the description states that the attacker can execute code over a network. When an attacker delivers a crafted input to Edge, the type confusion allows arbitrary code execution, potentially compromising confidentiality, integrity, and availability of affected systems.
OpenCVE Enrichment