Impact
A use‑after‑free flaw exists in Microsoft Edge (Chromium‑based) that allows an attacker with network proximity to a victim to elevate privileges. By triggering the memory management bug, the attacker can obtain higher authority on the target system beyond the privileges originally granted to the user. This breach of integrity can lead to further exploitation, data theft, or persistent footh After Free, classified as CWE‑416.
Affected Systems
The vulnerability impacts Microsoft Edge (Chromium‑based) on any affected version for which a patch has not yet been installed. Current version information is not specified in the advisory, so all installations using the Chromium‑based Edge build must be considered at risk until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity issue. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑proximate attacker that can lure or manipulate a user into visiting a malicious site or loading malicious content in Edge. Because it is a memory‑corruption bug, exploitation requires code‑execution capabilities that may not be readily available to all threat actors, further reducing risk but not eliminating it.
OpenCVE Enrichment