Moderate CVSS 4.7 EPSS 0.00364 2025-09 archive

Executive Summary

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Overview

4.7
CVSS MEDIUM
Moderate
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Security Feature Bypass
Released Sep 9 2025
Last Updated Sep 9 2025
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00364 — 0.28124 percentile

CVSS Vector

ATTACK VECTOR
Network
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Changed
Temporal Score: 4.1

EPSS Score

0.00364
probability of exploitation in the next 30 days
0.28124 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Microsoft Edge (Chromium-based) Release Notes (Security Update) Moderate Security Feature Bypass No

Patches

1 patch
Article Type Restart
Release Notes Security Update No

Known Exploits

Acknowledgments

Mingi Jung with WebSec