Description
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Published: 2026-07-03
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An absolute path traversal flaw exists in Microsoft Edge (Chromium-based) for Android that enables an unauthorized attacker to read local files on the device. The weakness, classified as CWE‑36, can expose sensitive data stored within the device’s file system, but it does not allow code execution or remote control.

Affected Systems

The vulnerability impacts Microsoft Edge (Chromium-based) installations on Android devices. No specific version range is listed, implying that any Edge for Android deployment may be vulnerable until Microsoft releases an update.

Risk and Exploitability

The CVSS score of 6.2 signals a moderate risk. The EPSS score of < 1% and absence from the CISA KEV catalog suggest that widespread exploitation is unlikely at present. The likely attack vector is local access; an attacker must be able to interact with the device’s local environment to trigger the path traversal, and the flaw does not provide remote code execution.

Generated by OpenCVE AI on July 21, 2026 at 09:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for Microsoft Edge on the Android device via the Microsoft Update Guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58300).
  • If an update is not yet available, restrict Edge’s access to the file system by adjusting application permissions or disabling the app until a patch is applied.
  • Ensure the Android operating system is current with all security patches to reduce the overall risk of exploitation.

Generated by OpenCVE AI on July 21, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Title Microsoft Edge for Android Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-36
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:45.284Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58300

cve-icon Vulnrichment

Updated: 2026-07-06T14:26:27.799Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:15:02Z

Weaknesses
  • CWE-36

    Absolute Path Traversal