Impact
A flaw in Microsoft Edge for Android permits the exposure of private personal information to an unauthorized actor, enabling data disclosure over a network. The vulnerability is classified as an Information Exposure flaw (CWE-359).
Affected Systems
Microsoft Edge for Android (Chromium-based) running on Android devices. No specific affected versions are listed in the available data, so all releases of the browser that lack the most recent updates may be vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is over a network connection; the CVE does not describe the need for malicious content or extensions, so a generic network-based attack is inferred assessment is who has not applied the latest browser updates could potentially be exposed.
OpenCVE Enrichment