Description
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-07-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. The flaw means the browser fails to enforce its intended protection, allowing remote traffic to remove or disable that feature.

Affected Systems

Microsoft Edge (Chromium‑based) browsers installed on Android devices. No specific version is identified, so the vulnerability may affect any recent instance of Edge on Android until a vendor fix is deployed.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1 % suggests exploitation is considered unlikely at the time of reporting. The issue is not listed in CISA KEV. Based on the description, the attack vector appears to be remote over a network: a malicious party can send specially crafted traffic to the browser to exploit the improper access control and bypass the protection. Local privilege escalation is not required.

Generated by OpenCVE AI on July 24, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Edge for Android update that addresses the improper access control flaw.
  • If a patch is not yet available, restrict Edge’s network traffic to the endpoints associated with the security feature or use Android’s firewall to block suspicious connections.
  • Consider disabling the affected security feature through device policy or configuration until the patch is applied.

Generated by OpenCVE AI on July 24, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
Title Microsoft Edge for Android Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-24T19:36:02.078Z

Reserved: 2026-07-01T04:33:41.869Z

Link: CVE-2026-58523

cve-icon Vulnrichment

Updated: 2026-07-07T02:21:07.557Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T10:30:09Z

Weaknesses