CVE-2022-33649 is a critical security feature bypass vulnerability affecting Microsoft Edge (Chromium-based) with a CVSS score of 9.6. This flaw allows an unauthenticated attacker to execute arbitrary code with high impact on confidentiality, integrity, and availability, requiring user interaction via a low complexity network attack. While not currently listed in CISA's KEV catalog and lacking public exploit intelligence (Metasploit, Nuclei, ExploitDB), its high FAUCET Risk Score of 84/100 and notable media coverage suggest significant potential risk. Community discussion is limited, but its inclusion in Microsoft's August 2022 Patch Tuesday highlights its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 104.0.1293.47CPE matchmatch criteria | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.