Description
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-03
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Edge (Chromium-based) suffers from improper link resolution before file access "link following" that permits an unauthorized attacker to read the contents of local or network files and transmit that data over a network. The flaw is a CWE‑59 Path Traversal issue, leading to a loss of confidentiality only; it does not provide code execution or higher‑level privileges.

Affected Systems

All versions of Microsoft Edge (Chromium‑based) that have not applied the latest security update are potentially vulnerable. No specific version range is given, so any installed Edge that is not up‑to‑date may be affected.

Risk and Exploitability

The CVSS score of 7.4 indicates a high severity issue. The EPSS score is below 1%, suggesting that exploitation attempts are expected to be rare, and the vulnerability is not listed in CISA’s KEV catalog. The likely exploitation flow involves an attacker enticing a user to open a crafted link or visit a malicious webpage; once the browser follows that link, it can access the target file and send its contents back to the attacker, thereby exposing sensitive information.

Generated by OpenCVE AI on August 1, 2026 at 20:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge update that includes the security fix from Microsoft.
  • Enable automatic updates for Edge via Windows Update or the Microsoft Edge service to ensure timely application of patches.
  • Consider implementing a group policy or browser setting that blocks or restricts the "file:" URL scheme to prevent local file access from web pages.
  • Deploy web‑filtering or URL‑blacklisting controls to block suspicious or malicious URLs that could trigger the vulnerability.
  • Monitor outbound traffic from Edge for anomalous data exfiltration patterns as an early‑warning indicator of exploitation attempts.

Generated by OpenCVE AI on August 1, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Title Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-59
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:16:22.312Z

Reserved: 2026-06-26T17:45:44.854Z

Link: CVE-2026-57991

cve-icon Vulnrichment

Updated: 2026-07-06T11:31:17.251Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:02.180

Modified: 2026-07-07T12:43:02.303

Link: CVE-2026-57991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')