Impact
The vulnerability is a race condition caused by improper synchronization of a shared resource in Microsoft Edge (Chromium-based). It allows a user who can run arbitrary code in Edge to gain higher local privileges on the affected system. The flaw is captured by CWE-362, indicating a race condition that can be exploited by an attacker who can repeatedly trigger the condition before the system resolves the state, thereby escalating privileges without needing external access.
Affected Systems
The affected vendor is Microsoft and the product is Microsoft Edge (Chromium-based). Specific affected editions or build numbers were not disclosed, so all exposed installation versions may be vulnerable until an official patch is released.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high severity flaw. The EPSS score of 0.00193 indicates a very low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is local, requiring an authorized attacker with the ability to run arbitrary code within Edge. Exploitation would involve creating a malicious web page or local content that triggers the race condition, thereby granting the attacker elevated privileges on the host. Because the flaw does not require network access and can be triggered by a normal user who can open a browser, the likelihood of exploitation remains low but could be higher in environments with many users or insufficient privilege controls.
OpenCVE Enrichment