Impact
An absolute path traversal flaw in Microsoft Edge (Chromium‑based) for Android allows an unauthenticated attacker to read arbitrary local files on the device. The weakness, classified as CWE‑36, can expose sensitive data stored within the device’s file system, but it does not provide code execution, privilege escalation, or remote control capabilities.
Affected Systems
Microsoft Edge (Chromium‑based) running on Android devices is affected. No specific version range is identified in the advisory, implying that any deployment of Edge for Android could be vulnerable until Microsoft releases a patch.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate risk to confidentiality. The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest that exploitation is presently uncommon. The likely attack vector is local; an adversary must be able to interact with the device’s local environment to trigger the path traversal. No remote exploitation is possible, but any locally accessible data that the browser can traverse may be disclosed.
OpenCVE Enrichment