Executive brief
A vulnerability in the Microsoft Edge web browser could allow an attacker to access sensitive information over a network. This occurs when the browser improperly handles file names or paths provided by external sources. An attacker could exploit this to view files or data they are not authorized to see, potentially compromising user privacy or corporate data.
Technical details
A vulnerability classified as CWE-73 (External Control of File Name or Path) exists in Microsoft Edge (Chromium-based). The flaw allows an unauthenticated remote attacker to influence file paths used by the browser, leading to unauthorized information disclosure. Exploitation requires a user to interact with a malicious link or website (User Interaction: Required). Successful exploitation results in a high impact on confidentiality as the attacker can access data across security boundaries (Scope: Changed). Microsoft has released security updates to address this issue.
Affected products
- Microsoft Edge (Chromium-based)
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft published the security update guide for this vulnerability.