Description
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Published: 2026-07-03
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A relative path traversal flaw exists in Microsoft Edge for Android that allows an unauthorized user to read files stored on the device. The vulnerability permits access to data that resides locally, compromising confidentiality without providing a path to code execution or denial‑of‑service. The weakness aligns with CWE‑23, where an attacker can manipulate file paths to read unintended resources.

Affected Systems

All installations of Microsoft Edge (Chromium-based) for Android that have not received the recent security update are potentially vulnerable. Specific version numbers are not listed in the advisory, so any build lacking the fix could be affected.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. An EPSS score of <1% shows that exploitation in the wild is unlikely, and the vulnerability is not included in CISA's KEV catalog. Based on the description, the likely attack vector is local, as the flaw requires direct device access to manipulate file paths. The primary impact is loss of confidentiality of locally stored information.

Generated by OpenCVE AI on August 1, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest Microsoft Edge (Chromium-based) for Android from the Google Play Store; the released build contains the patch for this vulnerability.
  • If an updated version is not yet available, consider disabling or uninstalling Microsoft Edge from the device until the fix is delivered.
  • Maintain awareness of Microsoft security updates by regularly checking the Microsoft Security Response Center and the Play Store for the latest release; apply any new update promptly.

Generated by OpenCVE AI on August 1, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Title Microsoft Edge for Android Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-23
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Google Android
Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:20:57.115Z

Reserved: 2026-07-01T04:33:41.869Z

Link: CVE-2026-58522

cve-icon Vulnrichment

Updated: 2026-07-06T11:35:40.296Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T21:17:05.883

Modified: 2026-07-07T22:52:45.193

Link: CVE-2026-58522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T20:15:04Z

Weaknesses
  • CWE-23

    Relative Path Traversal