Impact
An absolute path traversal flaw exists in Microsoft Edge (Chromium-based) for Android that enables an unauthorized attacker to read local files on the device. The weakness, classified as CWE‑36, can expose sensitive data stored within the device’s file system, but it does not allow code execution or remote control.
Affected Systems
The vulnerability impacts Microsoft Edge (Chromium-based) installations on Android devices. No specific version range is listed, implying that any Edge for Android deployment may be vulnerable until Microsoft releases an update.
Risk and Exploitability
The CVSS score of 6.2 signals a moderate risk. The EPSS score of < 1% and absence from the CISA KEV catalog suggest that widespread exploitation is unlikely at present. The likely attack vector is local access; an attacker must be able to interact with the device’s local environment to trigger the path traversal, and the flaw does not provide remote code execution.
OpenCVE Enrichment