Impact
A relative path traversal flaw exists in Microsoft Edge for Android that allows an unauthorized user to read files stored on the device. The vulnerability permits access to data that resides locally, compromising confidentiality without providing a path to code execution or denial‑of‑service. The weakness aligns with CWE‑23, where an attacker can manipulate file paths to read unintended resources.
Affected Systems
All installations of Microsoft Edge (Chromium-based) for Android that have not received the recent security update are potentially vulnerable. Specific version numbers are not listed in the advisory, so any build lacking the fix could be affected.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. An EPSS score of <1% shows that exploitation in the wild is unlikely, and the vulnerability is not included in CISA's KEV catalog. Based on the description, the likely attack vector is local, as the flaw requires direct device access to manipulate file paths. The primary impact is loss of confidentiality of locally stored information.
OpenCVE Enrichment