Description
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Published: 2026-07-03
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An absolute path traversal flaw in Microsoft Edge (Chromium‑based) for Android allows an unauthenticated attacker to read arbitrary local files on the device. The weakness, classified as CWE‑36, can expose sensitive data stored within the device’s file system, but it does not provide code execution, privilege escalation, or remote control capabilities.

Affected Systems

Microsoft Edge (Chromium‑based) running on Android devices is affected. No specific version range is identified in the advisory, implying that any deployment of Edge for Android could be vulnerable until Microsoft releases a patch.

Risk and Exploitability

The CVSS score of 6.2 indicates a moderate risk to confidentiality. The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest that exploitation is presently uncommon. The likely attack vector is local; an adversary must be able to interact with the device’s local environment to trigger the path traversal. No remote exploitation is possible, but any locally accessible data that the browser can traverse may be disclosed.

Generated by OpenCVE AI on August 1, 2026 at 20:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge security update for Android available through the Microsoft Update Guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58300).
  • If no update is currently released, restrict the Edge application’s file‑system access by modifying its Android permissions or temporarily disable/uninstall the app until the patch is applied.
  • Keep the Android operating system and all related security updates current, as they reduce the overall attack surface and may mitigate related local vulnerabilities.

Generated by OpenCVE AI on August 1, 2026 at 20:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Title Microsoft Edge for Android Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-36
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Google Android
Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:56.650Z

Reserved: 2026-06-29T21:59:30.871Z

Link: CVE-2026-58300

cve-icon Vulnrichment

Updated: 2026-07-06T14:26:27.799Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:05.023

Modified: 2026-07-07T22:48:09.547

Link: CVE-2026-58300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses
  • CWE-36

    Absolute Path Traversal