Microsoft Edge
cpe:2.3:a:microsoft:edge:*:*:*:*:*:*:*
A type confusion vulnerability has been identified in Microsoft Edge (Chromium-based), specifically in version 150.0.4078.48. This vulnerability allows an unauthorized attacker to execute code remotely over the network. The issue arises from improper handling of resources, enabling exploitation by crafting deceptive elements that a user must interact with.
Exploitation of this vulnerability could lead to unauthorized remote code execution.
To reproduce this vulnerability, an attacker would need to host a specially crafted website designed to exploit the type confusion issue in Microsoft Edge (Chromium-based) version 150.0.4078.48. The attacker would then have to convince a user to visit the website, potentially through an email or message enticement, or by sending an attachment that prompts the user to open it.
Users can download the security update for Microsoft Edge (Chromium-based) version 150.0.4078.48 from the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.