Impact
The vulnerability is an improper neutralization of user‑provided input during web page generation, which is a classic cross‑site scripting weakness. An attacker can exploit this flaw to inject malicious scripts that cause a web page or application to appear as though it originates from a other sensitive information. The vulnerability does not provide direct code execution or arbitrary data access; its primary impact is graphical or content spoofing via injected malicious content.
Affected Systems
Microsoft Edge (Chromium‑based) is the affected product. The CVE does not specify any particular release or build numbers, so all versions of the Chromium‑based Edge browser are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.1 places this bug EPSS score is less than 1%, indicating a low probability of page content, the risk is higher in environments where internal networks allow users to view untrusted web content. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread, actively exploited instances have been reported yet, but the existence of the flaw warrants immediate remediation to prevent potential spoofing incidents.
OpenCVE Enrichment