Impact
Microsoft Edge for Android has a flaw that lets an attacker control the file name or path it uses, which can cause sensitive data to be sent out over the network. This issue stems from improper restriction of file system operations (CWE-73). As a result, an unauthorized party could potentially read local files or access data that should remain private. The flaw is specifically triggered when the browser processes a maliciously crafted URL or page that includes the attacker‑controlled path.
Affected Systems
The affected product is Microsoft Edge (Chromium‑based) for Android. No specific version range is provided, so any installation that still receives this vulnerability should be improved by updating to the latest available release.
Risk and Exploitability
The CVSS score of 7.4 reflects a high‑severity risk. Because the EPSS score is not available, the likelihood of exploitation at this time is unclear, and the vulnerability has not yet been reported in the CISA KEV catalog. Attackers would likely use a malicious website or link that the user visits in Edge to trigger the flaw. Successful exploitation could enable the attacker to transmit the disclosed information over a network to a remote host.
OpenCVE Enrichment