Description
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Microsoft Edge for Android is a CWE‑359 information‑exposure defect that allows an unauthorized actor to read private personal information from the browser and transmit it externally. This vulnerability undermines data confidentiality because the application fails to properly restrict the scope of data that can be shared or revealed.

Affected Systems

Microsoft Edge for Android (Chromium‑based). No specific version is indicated in the advisory, so all current builds are potentially affected until a fix is applied.

Risk and Exploitability

The CVSS score of 7.1 places this issue in the moderate‑to‑high severity range. The EPSS score is less than 1 %, indicating a low probability of exploitation, and the vulnerability is not included in CISA’s KEV catalog. Based on the description, the likely attack vector is remote over a network, where an attacker can interact with the app to trigger the data disclosure.

Generated by OpenCVE AI on July 21, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge for Android update via the Google Play Store; the vendor patch resolves the CWE‑359 information‑exposure defect.
  • Disable browsing data sharing and third‑party access in Edge’s privacy settings to prevent cross‑app leakage.
  • Restr‑level permissions until the patch is applied.

Generated by OpenCVE AI on July 21, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
Title Microsoft Edge for Android Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-359
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:43.184Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58296

cve-icon Vulnrichment

Updated: 2026-07-06T15:16:37.734Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor