Impact
The flaw in Microsoft Edge for Android is a CWE‑359 information‑exposure defect that allows an unauthorized actor to read private personal information from the browser and transmit it externally. This vulnerability undermines data confidentiality because the application fails to properly restrict the scope of data that can be shared or revealed.
Affected Systems
Microsoft Edge for Android (Chromium‑based). No specific version is indicated in the advisory, so all current builds are potentially affected until a fix is applied.
Risk and Exploitability
The CVSS score of 7.1 places this issue in the moderate‑to‑high severity range. The EPSS score is less than 1 %, indicating a low probability of exploitation, and the vulnerability is not included in CISA’s KEV catalog. Based on the description, the likely attack vector is remote over a network, where an attacker can interact with the app to trigger the data disclosure.
OpenCVE Enrichment