Impact
The vulnerability stems from external control over file names or paths in Microsoft Edge for Android, allowing an attacker to read arbitrary local files. This flaw, identified as CWE‑73, can expose sensitive data residing on the device, thereby compromising confidentiality. The affected component lacks adequate sandbox controls to prevent such file system traversal.
Affected Systems
Microsoft Edge for Android is the product impacted by this flaw. No versioned information is supplied, so any unpatched installation of the Android browser is presumed vulnerable. The issue is specific to the Android edition and does not affect other operating systems.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity for information disclosure, although EPSS is unavailable, leaving the probability of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at the time of this analysis. The most plausible attack scenario involves a local attacker who can provide a malicious file path to Edge, potentially through a crafted URL or an intent from another application. Until a public exploit is discovered, the risk remains theoretically high rather than practically demonstrable.
OpenCVE Enrichment