Description
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Published: 2026-07-03
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a relative path traversal flaw in Microsoft Edge for Android that permits an attacker who can execute code or otherwise interact with the device locally to read data stored on the device. This allows disclosure of information that exists on the filesystem at the time of exploitation, thereby compromising confidentiality. The weakness aligns with CWE‑23, indicating improper handling of file paths. No additional properties such as privilege escalation, code execution, or denial of service are documented in the provided information.

Affected Systems

Microsoft Edge (Chromium-based) for Android is affected. Version details are not disclosed in the advisory, so any installation that does not include the recent secure build may be vulnerable.

Risk and Exploitability

The CVSS score of 6.8 reflects a moderate severity classification. The EPSS score of <1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the description specifies local information disclosure, the attack vector is inferred to be local; the attacker must have the ability to interact with the device to trigger the flaw. The impact is primarily to confidentiality, with no evidence of capabilities to modify data, execute code, or deny service.

Generated by OpenCVE AI on July 17, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Edge (Chromium-based) for Android from the Google Play Store, which includes the patch for CVE‑2026‑58522.
  • If an update is not yet available, uninstall or disable Microsoft Edge on the device until a fixed version is released.
  • Regularly check the Microsoft Security Response Center and the Google Play Store for the latest update and apply it promptly.

Generated by OpenCVE AI on July 17, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Title Microsoft Edge for Android Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-23
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T00:00:45.908Z

Reserved: 2026-07-01T04:33:41.869Z

Link: CVE-2026-58522

cve-icon Vulnrichment

Updated: 2026-07-06T11:35:40.296Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T09:45:04Z

Weaknesses
  • CWE-23

    Relative Path Traversal