Impact
The vulnerability is a relative path traversal flaw in Microsoft Edge for Android that permits an attacker who can execute code or otherwise interact with the device locally to read data stored on the device. This allows disclosure of information that exists on the filesystem at the time of exploitation, thereby compromising confidentiality. The weakness aligns with CWE‑23, indicating improper handling of file paths. No additional properties such as privilege escalation, code execution, or denial of service are documented in the provided information.
Affected Systems
Microsoft Edge (Chromium-based) for Android is affected. Version details are not disclosed in the advisory, so any installation that does not include the recent secure build may be vulnerable.
Risk and Exploitability
The CVSS score of 6.8 reflects a moderate severity classification. The EPSS score of <1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the description specifies local information disclosure, the attack vector is inferred to be local; the attacker must have the ability to interact with the device to trigger the flaw. The impact is primarily to confidentiality, with no evidence of capabilities to modify data, execute code, or deny service.
OpenCVE Enrichment